URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.121.14.176
Firstseen:2025-12-12 18:20:06 UTC
Total malware sites :25
Online malware sites :0 (0%)
Offline Malware sites :25 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-12 18:20:11 185.121.14.176Not listedAS50053 VDSKA-AS- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-01 21:52:17http://185.121.14.176/armv7lOfflineDDoSAgent elf ua-wget NDA0E
2026-01-01 21:51:24http://185.121.14.176/mipsOfflineelf mirai ext ua-wget NDA0E
2026-01-01 21:51:24http://185.121.14.176/mips64Offlineelf ua-wget NDA0E
2026-01-01 21:51:24http://185.121.14.176/arm7OfflineDDoSAgent elf ua-wget NDA0E
2026-01-01 21:51:24http://185.121.14.176/bot.armOfflineelf ua-wget NDA0E
2026-01-01 21:51:24http://185.121.14.176/s390xOfflineDDoSAgent elf ua-wget NDA0E
2026-01-01 21:51:24http://185.121.14.176/mipsleOfflineelf ua-wget NDA0E
2026-01-01 21:51:24http://185.121.14.176/x86OfflineDDoSAgent elf ua-wget NDA0E
2026-01-01 21:51:23http://185.121.14.176/ppcOfflineDDoSAgent elf ua-wget NDA0E
2026-01-01 21:51:23http://185.121.14.176/i586OfflineDDoSAgent elf ua-wget NDA0E
2026-01-01 21:51:23http://185.121.14.176/mips64leOfflineelf ua-wget NDA0E
2026-01-01 21:45:15http://185.121.14.176/x86_64Offlineelf ua-wget NDA0E
2025-12-12 18:20:15http://185.121.14.176/arm6.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:14http://185.121.14.176/mips.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/sh4.SakuraOfflinemirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/powerpc.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/arm5.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/arm4.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/mipsel.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/Sakura.shOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/i586.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/arm7.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/x86_64.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/i686.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre
2025-12-12 18:20:11http://185.121.14.176/m68k.SakuraOfflinegafgyt ext mirai ext opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-14 13:53:564c8d73003514cbc68154a98fe8700bd7a248d6b655bef29516c547c6e86ebadfelfDDoSAgent
2026-01-14 13:52:00b5ecbca7df8b6bb636300a260b6295be0207d3be29a298dce61f7c4a94a3dd66elfDDoSAgent
2026-01-14 13:46:304c8d73003514cbc68154a98fe8700bd7a248d6b655bef29516c547c6e86ebadfelfDDoSAgent
2026-01-14 13:14:5489f276c4615636a259830cc80417eb2837e09d826543ad72d9ed45a6bcc2644aelfDDoSAgent
2026-01-14 13:04:35b5ecbca7df8b6bb636300a260b6295be0207d3be29a298dce61f7c4a94a3dd66elfDDoSAgent
2026-01-14 12:55:345f7bf5a001d110a03fcc9c974a3e126438a287b0c6ece5528b1b76ac59c9bdbcelfDDoSAgent
2026-01-01 21:52:17e63fa533fec8b8089ff5878389cdf93d42eb64e9fe8e48d0dab3b0cdc5bb737celf 
2026-01-01 21:51:24beb8cbd6be2c822688fe3f7835660fda7731c302e51b8745d413b693a50d1681elfMirai
2026-01-01 21:51:24fd7b5fd23aed0b89fefa4a9261154affea7681d51378656088e38bf8cd27faa6elf 
2026-01-01 21:51:24e63fa533fec8b8089ff5878389cdf93d42eb64e9fe8e48d0dab3b0cdc5bb737celf 
2026-01-01 21:51:2480188044b0c4e83cbbcee1d5ed7c9afa08a77f4caadb377148f56b8061ef80d2elf 
2026-01-01 21:51:24dd5b6e6d1b5901211029e81795ea59281c2aeeb1188e9738f7732c51e629fa43elf 
2026-01-01 21:51:24b3eadaae58e6f843c78f7aeec2846512e22a3d3fa7b6141fa93b46562fc22569elf 
2026-01-01 21:51:230113da9f6ca2e13c26a475550f5910eab7f33025856a8ee4a719d1e3d488bccdelf 
2026-01-01 21:51:230113da9f6ca2e13c26a475550f5910eab7f33025856a8ee4a719d1e3d488bccdelf 
2026-01-01 21:51:230f1a9c03fa7bf1525b34406245dd6ec3bf28a1f951b5b80a84732d0f1ac9aefcelf 
2026-01-01 21:51:2341558711b8159b4b5d686133941f1c3f62cabb7aefcbb95cfbca48473fbf1ee5elf 
2026-01-01 21:45:151e8dcf82caf62fb4950abbf62744d0ee8ad6782c7d3863f81c3d94f279e9c7e7elf 
2025-12-12 18:20:15125f499012edc6534dffa3b09899bdc20890e74938c82a54a81da35a6d2c6680elfGafgyt
2025-12-12 18:20:14f69fcf30eb52d7c0a517f0342bdd3ca80af987e6d20ffba2f0e69001a5ef7076elfGafgyt
2025-12-12 18:20:11025a635c98791f0c2f2498e58f1337bc69573b5390a6325fda79ec21a500b92eelf  
2025-12-12 18:20:115cf788b4998959370e950fc17b05f43f2a7c5451190807c4567706b82e8847d6elfGafgyt
2025-12-12 18:20:116a0b377d9084556b31da46a9ddde4f3994fe47ddb391b0cfb2e492ea5f1f09e5elfGafgyt
2025-12-12 18:20:11c3092111ffa42da764ad13fd8ce86cb9275043a8fcc28f2b777f37a27063c016elfGafgyt
2025-12-12 18:20:117832769ad06fa3451f7cf9caf998ce7664dc8c4e3c822081be6d3e5308ddd8b0elfGafgyt
2025-12-12 18:20:11463151ea89ac13b9ef0f97b3878f70ecc3a3bc17de5102244745c4a2c9ec6833elfGafgyt
2025-12-12 18:20:11bf23ada4496bd18a02fb81323482cce0cc07d81eaaa68557199a2b6721ac7cefelfGafgyt
2025-12-12 18:20:11f58a58117616dbb54d010dbe90fe9513005118c18baa699282c39c7af34e6005elfGafgyt
2025-12-12 18:20:114c240dd7fae03f36b7f470bed60dfc3aaaea3bd6493403f9f3f40cb61b4a86e3elfGafgyt
2025-12-12 18:20:1003252c6ef5927f6135a2a20f346678fec3150454d6e43b0e75a26722052d8610elfGafgyt
2025-12-12 18:20:10d7e4e6df87f3cbe30a24e6b6b8df6d8d0f1e9251f60261d578fc115b24586011shGafgyt