URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.132.53.139
Firstseen:2020-04-15 12:52:03 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-15 12:52:03 185.132.53.139SBL692133AS211507 lain- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-05-05 21:24:12http://185.132.53.139/arm7Offlinearm elf mirai ext ua-wget botnetkiller
2026-05-05 21:24:12http://185.132.53.139/mpslOfflineelf mips mirai ext ua-wget botnetkiller
2026-05-05 21:24:12http://185.132.53.139/arm5Offlinearm elf mirai ext ua-wget botnetkiller
2026-05-05 21:24:12http://185.132.53.139/arm4Offlinearm elf mirai ext ua-wget botnetkiller
2026-05-05 21:24:12http://185.132.53.139/tplink.shOfflinemirai ext sh ua-wget botnetkiller
2020-04-15 12:57:05http://185.132.53.139/sh4Offlinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:57:03http://185.132.53.139/armv6lOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:56:08http://185.132.53.139/x86Offlinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:56:06http://185.132.53.139/powerpcOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:56:04http://185.132.53.139/armv4lOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:56:02http://185.132.53.139/m68kOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:52:21http://185.132.53.139/mipselOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:52:19http://185.132.53.139/yoyobins.shOfflineshellscript zbetcheckin
2020-04-15 12:52:12http://185.132.53.139/sparcOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:52:10http://185.132.53.139/armv5lOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:52:08http://185.132.53.139/mipsOfflinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:52:06http://185.132.53.139/i586Offlinebashlite elf gafgyt ext zbetcheckin
2020-04-15 12:52:03http://185.132.53.139/i686Offlinebashlite elf gafgyt ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-05 21:24:12474b6d433fc53e29227a171d55ac605bdf39bdc7873b5dd25dd0a0ab62357810elfMirai
2026-05-05 21:24:12e515a628b303793229c075fc218329d5d679251e048f57f4190443cf4d5b7328elfMirai
2026-05-05 21:24:11ebef77f3cd6b09a7c4bb28f370c13913bf5b29edef0b7e1824babe5e7cbb5d3belfMirai
2026-05-05 21:24:118462b3577ddd71ba22f1e50a27ecb9f628a2731cdf1268ddee37eb322d0f5653elfMirai
2026-05-05 21:24:11d5da513c4c0567e80d7000cfbc283b0654c62245049c5bad70f2496f7656cfefshMirai
2020-04-15 12:57:05127382d3320fda033a170e38518074efc0c883a1ace5d6cdd99783c9d30e19a5elf  
2020-04-15 12:57:03de3b4a5ff5456d751ae07472fdc84ab579a6cecd5997887aa7aeea6a109e5edeelf  
2020-04-15 12:56:0884c81fd79fc3a19e2293fd47ec067b79d170ec7c22cfc8a04ac8e72ddec7779delf  
2020-04-15 12:56:067fe79f753250ecf4337732345a872e9a54ace866eb48339580919d5bf3042938elf  
2020-04-15 12:56:04d150fab591685175cf4ff1b79654f201e31c5b3a59a9aab6262172e78cabddd2elf  
2020-04-15 12:56:02f3fb1957aeee848dfea65e4cfe03718a805176b95921f930e5fdedc3afc46e01elf  
2020-04-15 12:52:2166919163c31530f41a95b1a33276056ba48c93a3a2f05371a1fe26ee3010b94celf  
2020-04-15 12:52:1936b9f5cfffcdc173aac539f2be20d8059b076195bdbb005030834b268c812869unknown  
2020-04-15 12:52:12b085919a110c2bc74459c946318826933dd4ec0a2726a1df212fd7d46a66a243elf  
2020-04-15 12:52:107522f755b9c3a7c5b2d8d77599cc03ae3573bedd9a49408bd763ac363d16741felf  
2020-04-15 12:52:08036fea7927ae27193d9d752f33769fd10fb13e2b48e7b535e481a1e633cd561delf  
2020-04-15 12:52:06feee7517e3304c22265ef13868ac8b9ea77bbf77d1304129381d2b260fd244c3elf  
2020-04-15 12:52:03826340e2c4f54b7279f1916d81e3482bbdd8d8fc48884ffc5905874d349cac4eelf