URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 172.86.114.147
Firstseen:2026-02-16 13:16:05 UTC
Total malware sites :22
Online malware sites :6 (27%)
Offline Malware sites :16 (73%)
Newest active malware site :2026-02-17 00:06:16 UTC
Oldest active malware site :2026-02-17 00:04:17 UTC (Age: 3 hours, 48 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-16 13:16:12 172.86.114.147147.114.86.172.static.cloudzy.comNot listedAS14956 ROUTERHOSTING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-17 00:06:16http://172.86.114.147/shOnlineelf mirai ext ua-wget ClearlyNotB
2026-02-17 00:05:21http://172.86.114.147/sshdOnlineelf mirai ext ua-wget ClearlyNotB
2026-02-17 00:05:16http://172.86.114.147/opensshOnlineelf mirai ext ua-wget ClearlyNotB
2026-02-17 00:05:07http://172.86.114.147/cronOnlineelf mirai ext ua-wget ClearlyNotB
2026-02-17 00:04:17http://172.86.114.147/pftpOnlineelf gafgyt ext ua-wget ClearlyNotB
2026-02-17 00:04:17http://172.86.114.147/ntpdOnlineelf mirai ext ua-wget ClearlyNotB
2026-02-16 15:38:21http://172.86.114.147/x-8.6-4.ISISOfflineelf ua-wget abuse_ch
2026-02-16 13:32:07http://172.86.114.147/m-i.p-s.ISISOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/x-3.2-.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/p-p.c-.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/a-r.m-6.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/ISIS.shOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/a-r.m-8.ISISOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/a-r.m-7.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/a-r.m-5.ISISOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/x-8.6-.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/i-5.8-6.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/m-p.s-l.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/p-o.w-e.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/s-h.4-.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/m-6.8-k.ISISOfflinemirai ext opendir DaveLikesMalwre
2026-02-16 13:16:12http://172.86.114.147/a-r.m-4.ISISOfflinegafgyt ext mirai ext opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-17 00:06:16f76cb52a25ce16209994cefe09b819fae41b7375a4f63d114fb8968cc36d0c2eelfMirai
2026-02-17 00:05:2042a838a30674fbe98000a59d99697ba6f874e07f422f0c957c832f64af8d3b5felfMirai
2026-02-17 00:05:16a55c7895e856356915105936f3a850521fc8ded24cae1e6320d72ddcc0d46a27elfMirai
2026-02-17 00:05:07b222ae3e2a14c2ba960f174595923c4db3d90030e92ba8f2c45e39c8a4914861elfMirai
2026-02-17 00:04:17210c6a24361ef65a2950cc37aee4f95bc51c4f91db9875f8cd58b876b1af9602elfGafgyt
2026-02-17 00:04:17f557a12aedb5bb9e26abd4f780f7e48e1bdc34424d24218f1e413ff32d6d66ddelfMirai
2026-02-16 13:32:0744784c5a34d7717b7ed839aaa2b5ca328f09731b332e33cca96ac84ddd80fc71elfGafgyt
2026-02-16 13:16:1251aa8460ad34b0fd3886b270753a2715fd52739b2f49d45e5302f6cccedf9d28elfGafgyt
2026-02-16 13:16:12a8bd0816fbb04f0e8f486f7cf20a0e7eb0f4667a3f54beeba003461e8de89c72elf  
2026-02-16 13:16:12965d294ec888f970825e6b865bba59ef9f7b078b26deaace6ac4ec4fee34479felf  
2026-02-16 13:16:1258b1f154738445f487602a7d39e7059ebfe5f82f2ca4be758c87e19458a09915elf  
2026-02-16 13:16:12c9120f89c56eaabb51acc09ee4ca558bf67a5226618d042896d7745852e540edelf  
2026-02-16 13:16:12b449241d9195058b6cb0f0847bf6a7af382ef0a8ea4455d7c961324e45a47955elfGafgyt
2026-02-16 13:16:12e187991a5b140801d2725c79b6c7d4555f0a61137160df338bcdabb9445f5533elf  
2026-02-16 13:16:12f85b0011c16fcb5ac92139bc99811ee97ca4e64c9298bf4871bd81e02e5be7d3elf  
2026-02-16 13:16:1272b6426fbcadf01145c42c5edfc3c43aea6feb27c1a2be1d042f7c25b2f86c81elf  
2026-02-16 13:16:1254dd32582e5d43016c57bfcfc055b260915938f23cd73d356ceb3ac12cecf910elf  
2026-02-16 13:16:129c307d31aa1917929b575c226b9c3109e6bee354b5edba6279285385f50352b7elf  
2026-02-16 13:16:12f16b5b54b679961af2f9edaca19971e4287f083c261055de1b8748fac030734felfGafgyt
2026-02-16 13:16:11ce02bc7cfe12e37d38293564331b57e58aa95666e2dc051e2104b4a5be9a56e8shGafgyt
2026-02-16 13:16:1112d4d11f3d599583147d8a714ad130e339efc78a0f07ce5cef8bf95ab2f2c534elf