URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.196.11.126
Firstseen:2025-12-28 11:30:06 UTC
Total malware sites :25
Online malware sites :0 (0%)
Offline Malware sites :25 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-28 11:30:21 185.196.11.126marlboroSBL640645AS42624 swissnetwork02- CHyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-29 12:06:37http://185.196.11.126/bins/.mpslOfflineelf ua-wget NDA0E
2025-12-29 12:06:37http://185.196.11.126/bins/.x64Offlineelf ua-wget NDA0E
2025-12-29 12:06:37http://185.196.11.126/bins/.spcOfflineelf ua-wget NDA0E
2025-12-29 12:06:36http://185.196.11.126/bins/.i586Offlineelf ua-wget NDA0E
2025-12-29 12:06:36http://185.196.11.126/bins/.mipsOfflineelf ua-wget NDA0E
2025-12-29 12:06:36http://185.196.11.126/bins/.x86Offlineelf ua-wget NDA0E
2025-12-29 12:06:36http://185.196.11.126/bins/.sh4Offlineelf ua-wget NDA0E
2025-12-29 12:06:35http://185.196.11.126/bins/.arm7Offlineelf ua-wget NDA0E
2025-12-29 12:06:35http://185.196.11.126/bins/.m68kOfflineelf ua-wget NDA0E
2025-12-29 12:06:34http://185.196.11.126/bins/.arm5Offlineelf ua-wget NDA0E
2025-12-29 12:06:33http://185.196.11.126/bins/.ppcOfflineelf ua-wget NDA0E
2025-12-29 12:06:33http://185.196.11.126/bins/.armOfflineelf ua-wget NDA0E
2025-12-29 07:40:34http://185.196.11.126/bins/hoho.mpslOfflineelf ua-wget abuse_ch
2025-12-29 07:40:34http://185.196.11.126/bins/hoho.arm7Offlineelf ua-wget abuse_ch
2025-12-29 07:40:33http://185.196.11.126/bins/hoho.ppcOfflineelf ua-wget abuse_ch
2025-12-29 07:40:33http://185.196.11.126/bins/hoho.sh4Offlineelf ua-wget abuse_ch
2025-12-29 07:40:33http://185.196.11.126/bins/hoho.arm5Offlineelf ua-wget abuse_ch
2025-12-29 07:40:33http://185.196.11.126/bins/hoho.mipsOfflineelf ua-wget abuse_ch
2025-12-29 07:40:33http://185.196.11.126/bins/hoho.x86Offlineelf ua-wget abuse_ch
2025-12-29 07:40:32http://185.196.11.126/bins/hoho.spcOfflineelf ua-wget abuse_ch
2025-12-29 07:40:32http://185.196.11.126/bins/hoho.armOfflineelf ua-wget abuse_ch
2025-12-29 07:40:32http://185.196.11.126/bins/hoho.arm6Offlineelf ua-wget abuse_ch
2025-12-29 07:40:32http://185.196.11.126/bins/hoho.m68kOfflineelf ua-wget abuse_ch
2025-12-29 07:40:21http://185.196.11.126/bins/.ppc-440fpOfflineascii geenensp
2025-12-28 11:30:21http://185.196.11.126/wget.shOfflineascii geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-12-28 13:48:330fc753e522b72222dc3ff1e4a1f3463db8e72a79f54eb3dedf901e13ec6af4e3sh