URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 168.220.248.106
Firstseen:2026-05-05 00:03:06 UTC
Total malware sites :18
Online malware sites :16 (89%)
Offline Malware sites :2 (11%)
Newest active malware site :2026-05-05 00:05:26 UTC
Oldest active malware site :2026-05-05 00:05:22 UTC (Age: 1 day, 12 hours, 36 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-05-05 00:03:27 168.220.248.106Not listedAS151734 WEBYNEDC-AS-IN- INyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf mirai ext botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Offlineelf mirai ext botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf mirai ext botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:26http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf gafgyt ext botnetkiller
2026-05-05 00:05:23http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf gafgyt ext botnetkiller
2026-05-05 00:05:23http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:05:22http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf gafgyt ext botnetkiller
2026-05-05 00:05:22http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf mirai ext botnetkiller
2026-05-05 00:05:22http://168.220.248.106:9087/payload/a6i3khk75wg...Onlineelf botnetkiller
2026-05-05 00:03:27http://168.220.248.106:9087/payload/a6i3khk75wg...Offlinesh botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-05 06:32:39fc7d0b63f0ba05f296c351a4626fff86305108c5e641dcafceda95a556dc111felfGafgyt
2026-05-05 06:30:0641c51222dd1546ad8c4dd5de3bf6926d8bc6fec696be2b2d9f36d9e9ed3f48fdelfMirai
2026-05-05 06:26:22a9f8bd78c5978ad065864ed3f5fd850cad4e2507d373ff442d4de98ec12f321celf 
2026-05-05 06:11:5481b42e8607ee4d1d2c3370fd6cbc2154df8680c4c5db15839c51e310a7b56bbeelf 
2026-05-05 06:00:24463565e54a75cf10afd005a779e4f5f8f7f44c40b2d3122f3f022ab3ab079574elf 
2026-05-05 05:58:012ac4db80b4fe6bf01ee24fbe10b40d1267ce5934895ee232e8fb3cdc6127f6cdelf 
2026-05-05 05:48:35cfaddbc9847b6e3ef2f7fc14bf619d63e00ad7f3322d9055ca0ee43ad42adcdbelfGafgyt
2026-05-05 05:48:354da108dee433daff7bfc182a4d56a47fc0759d37940f472bebf22dc4f5b8c578elf 
2026-05-05 05:46:30b546ec2bd3d9566bfd366075fe69c8a0fd832cf2673c4cda3fbe0dca52b79663elfMirai
2026-05-05 05:43:469341a4fbf520d11bf9d597766f6e217b3f84b8f616aa3806566d69eda77ca4caelf 
2026-05-05 05:43:3118df7c98df33cee3f0dba5f3764643cf74fb12ccbd5048006fa76b4191c22ec2elfMirai
2026-05-05 05:42:306a12d9282c1800bece91bbb6f981e463f0ae1b59a99d00642f2eda9adc376843elfGafgyt
2026-05-05 05:37:11267e0e1ae3cabbc8e6d35c01bdf315386447b3c2679f1aa04f2aedfbf1ac5777elf 
2026-05-05 05:31:02382ed9f8e4c5ef0e7272bc62518bf4ed7a93e0f3f6920269a22a128feada3a40elfMirai
2026-05-05 05:29:137de8cfd15e8cd59a012fce2be5f823558796e17deafe81d4725066ad3b912c49elf 
2026-05-05 05:28:4875edd5ccb17efdcadd5a0759d5727899a85c2ce2acaad08187a0c1c59204115delf 
2026-05-05 05:14:157f0b2b9e66f52f2f908d300681b64d1a8dde93a28f3249846b60a12fe5cacdc5elf