URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 189.252.214.199
Firstseen:2020-04-30 07:19:09 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-30 07:19:13http://189.252.214.199:46043/.iOffline32-bit arm elf hajime geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-05-18 16:08:1352ea1ddbbb7ad0c8b9b62815c651169f02c2d840468e5735afcbf0af0d295bb6elf  
2020-05-13 15:09:42e7b1e0d341de5d9e1dd08117cb4385ea11126a8b67ed5c10b1909041a2fb0059elf  
2020-05-01 18:26:4153ba444e2c5891205e72733afc683f92261a90c938f8980405b622b8df340cc1elf  
2020-04-30 10:31:0690a7d657b8266c8e1717f1d43d26ddf6a4905817ba486e7393f077234860b8caelf  
2020-04-30 07:19:12a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3elfHajime