URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.122.27.90
Firstseen:2024-12-13 08:48:04 UTC
Total malware sites :21
Online malware sites :11 (52%)
Offline Malware sites :10 (48%)
Newest active malware site :2025-11-08 12:07:07 UTC
Oldest active malware site :2025-11-08 12:06:06 UTC (Age: 15 days, 23 hours, 29 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-13 08:48:07 176.122.27.90Not listedAS48096 ITGRAD- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-08 12:07:07http://176.122.27.90/http.server/tmp4.elfOnlineGetShell opendir BlinkzSec
2025-11-08 12:06:13http://176.122.27.90/http.server/elf.exeOnlinemeterpreter opendir BlinkzSec
2025-11-08 12:06:13http://176.122.27.90/http.server/temp.elfOnlineConnectBack opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/http.server/tmp5.elfOnlineMetasploit opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/123.binOnlinemeterpreter opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/http.server/tmp.exeOnlinemeterpreter opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/http.server/sup.exeOnlinemeterpreter opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/http.server/reverse.elfOnlineConnectBack opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/http.server/tmp1.elfOnlineMetasploit opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/http.server/sys.exeOnlinemeterpreter opendir BlinkzSec
2025-11-08 12:06:06http://176.122.27.90/http.server/tmp.elfOnlineConnectBack opendir BlinkzSec
2024-12-17 07:01:23http://176.122.27.90:9999/sup.exeOfflinemeterpreter abus3reports
2024-12-17 07:01:18http://176.122.27.90:9999/sys.exeOfflinemeterpreter abus3reports
2024-12-17 07:01:13http://176.122.27.90:9999/elf.exeOfflinemeterpreter abus3reports
2024-12-13 08:50:07http://176.122.27.90:9999/tmp.elfOfflineConnectBack elf malware Metasploit opendir Joker
2024-12-13 08:49:06http://176.122.27.90:9999/temp.elfOfflineConnectBack elf malware Metasploit opendir Joker
2024-12-13 08:48:07http://176.122.27.90:9999/tmp5.elfOfflineelf malware Metasploit opendir Joker
2024-12-13 08:48:07http://176.122.27.90:9999/tmp.exeOfflineelf malware Metasploit meterpreter opendir Joker
2024-12-13 08:48:07http://176.122.27.90:9999/tmp4.elfOfflineelf GetShell malware Metasploit opendir Joker
2024-12-13 08:48:07http://176.122.27.90:9999/tmp1.elfOfflineelf malware Metasploit opendir Joker
2024-12-13 08:48:07http://176.122.27.90:9999/reverse.elfOfflineConnectBack elf malware Metasploit opendir Joker

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-08 12:07:07ac3f9676d7ad6c8964dfdd08d02c03e35ee8bcbec85e69704d893e5ce9c201e6elfGetShell
2025-11-08 12:06:13053542ef7ed95b8bb4cc040e732cf4fad01e24c3a60b3b1c3b1c794b6bcf8d55exeMeterpreter
2025-11-08 12:06:1213071bfbab50392760533f3f0b0f137808ef67852ce92ef6eddb9155266ec066elfConnectBack
2025-11-08 12:06:06448e0fc4cf6c14b29d710aff969b8b503f1e37d48e54d11cb7d3e97998c027fbelfMetasploit
2025-11-08 12:06:062aedff96fbbdf9b8ff5c973a011de14b98f49b8e2f4e38a2676fdc0f49274910dll Meterpreter
2025-11-08 12:06:06d459bd8e6ababe027af56fc683181351be1d4ad230da087e742aaef5c0979811exeMeterpreter
2025-11-08 12:06:06d46988f81eb72e8587a297dfb345ea39eba96a9ba248041424fd8e2191a49cf7exeMeterpreter
2025-11-08 12:06:065b1f63d14a2fcfa377f101f9db31a5ba6e415795a2f1c2869946430155b6f626elfConnectBack
2025-11-08 12:06:06e134c4df61f494f43fe6fece16a1b8b33e69f022dab25df995c0e09468785edcelfMetasploit
2025-11-08 12:06:068d8f1b404e0e59a6ca4bf5f19120d8d89dd8a412d7516d900f53a004a6f02feeexe Meterpreter
2025-11-08 12:06:066fd4de5b20bb60bbc9d1cdc1619c2647652c08f454c96f927283af796cf1cf3eelfConnectBack
2024-12-17 07:01:22d46988f81eb72e8587a297dfb345ea39eba96a9ba248041424fd8e2191a49cf7exeMeterpreter
2024-12-17 07:01:178d8f1b404e0e59a6ca4bf5f19120d8d89dd8a412d7516d900f53a004a6f02feeexe Meterpreter
2024-12-17 07:01:13053542ef7ed95b8bb4cc040e732cf4fad01e24c3a60b3b1c3b1c794b6bcf8d55exeMeterpreter
2024-12-13 08:50:076fd4de5b20bb60bbc9d1cdc1619c2647652c08f454c96f927283af796cf1cf3eelfConnectBack
2024-12-13 08:49:0613071bfbab50392760533f3f0b0f137808ef67852ce92ef6eddb9155266ec066elfConnectBack
2024-12-13 08:48:06448e0fc4cf6c14b29d710aff969b8b503f1e37d48e54d11cb7d3e97998c027fbelfMetasploit
2024-12-13 08:48:06d459bd8e6ababe027af56fc683181351be1d4ad230da087e742aaef5c0979811exeMeterpreter
2024-12-13 08:48:06ac3f9676d7ad6c8964dfdd08d02c03e35ee8bcbec85e69704d893e5ce9c201e6elfGetShell
2024-12-13 08:48:06e134c4df61f494f43fe6fece16a1b8b33e69f022dab25df995c0e09468785edcelfMetasploit
2024-12-13 08:48:065b1f63d14a2fcfa377f101f9db31a5ba6e415795a2f1c2869946430155b6f626elfConnectBack