URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.142.53.127
Firstseen:2025-10-11 21:01:05 UTC
Total malware sites :24
Online malware sites :0 (0%)
Offline Malware sites :24 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-11 21:01:08 192.142.53.127Not listedAS214036 ULTAHOST-AS- ZAyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-13 20:26:12http://192.142.53.127/html/cnr.shOfflinemirai ext sh BlinkzSec
2025-10-13 20:26:11http://192.142.53.127/html/dvr.shOfflinemirai ext sh BlinkzSec
2025-10-13 20:26:11http://192.142.53.127/html/yarn.shOfflinemirai ext sh BlinkzSec
2025-10-13 20:26:11http://192.142.53.127/html/tvt.shOfflinemirai ext sh BlinkzSec
2025-10-13 20:26:11http://192.142.53.127/html/jaws.shOfflinemirai ext sh BlinkzSec
2025-10-13 20:26:10http://192.142.53.127/html/faith.shOfflinemirai ext sh BlinkzSec
2025-10-13 20:25:12http://192.142.53.127/html/avtech.shOfflinemirai ext sh BlinkzSec
2025-10-13 20:25:12http://192.142.53.127/html/libdvr.shOfflinemirai ext sh BlinkzSec
2025-10-13 05:34:26http://192.142.53.127/ppcOfflineelf geofenced mirai ext PowerPC ua-wget USA botnetkiller
2025-10-13 05:34:21http://192.142.53.127/spcOfflineelf geofenced mirai ext sparc ua-wget USA botnetkiller
2025-10-13 05:34:20http://192.142.53.127/m68kOfflineelf geofenced m68k mirai ext ua-wget USA botnetkiller
2025-10-13 05:34:20http://192.142.53.127/x86_64Offlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-10-13 05:34:19http://192.142.53.127/massOfflinegeofenced mirai ext sh ua-wget USA botnetkiller
2025-10-13 05:34:18http://192.142.53.127/arm6Offlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-10-13 05:34:18http://192.142.53.127/i486Offlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-10-13 05:34:14http://192.142.53.127/sh4Offlineelf geofenced mirai ext SuperH ua-wget USA botnetkiller
2025-10-13 05:34:13http://192.142.53.127/x86Offlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-10-13 05:34:13http://192.142.53.127/arm7Offlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-10-13 05:34:13http://192.142.53.127/mipsOfflineelf geofenced mips mirai ext ua-wget USA botnetkiller
2025-10-13 05:34:13http://192.142.53.127/i686Offlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-10-13 05:34:12http://192.142.53.127/mpslOfflineelf geofenced mips mirai ext ua-wget USA botnetkiller
2025-10-13 05:34:09http://192.142.53.127/arm5Offlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-10-12 06:47:07http://192.142.53.127/yarn.shOfflineascii geenensp
2025-10-11 21:01:08http://192.142.53.127/armOfflineMozi ext threatquery

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-13 20:26:1251e37873ee8098d11b8f6aef0b75fd3979cf8ab70c0f507d3e7354dcaf5d7473shMirai
2025-10-13 20:26:112c07c0af480731bc946ef69a0238c54f45586f7907c99b03ae84587908d78f1dshMirai
2025-10-13 20:26:11d2eb78dc1d9a893c9abe10b883ac3a5317fcdd9ea01a4b2b18b6e4061d21e992shMirai
2025-10-13 20:26:11d40ca44aca0b3e9fec2f047ac4296fb6f0cc02ddd6cb4bcca6c228d4a77e7c95shMirai
2025-10-13 20:26:112e7b8b20114f302ee6f4c8b77a6a0dc7bd786c026f89f956d92dffa923c6450dshMirai
2025-10-13 20:26:1046a36628dc6cc3fcdf22a8b4a9e464694dde769942bd0511fa5ac67aac6b4040shMirai
2025-10-13 20:25:12aae9401a4d4dca9c78ec18d49658ecc1c03562de415064e9b3ffa60a312851f9shMirai
2025-10-13 20:25:12a13352d2ee7191a2a8cd4751c4a0fb1cb59c62985a34ba51eb934b71ee1ed827shMirai
2025-10-13 10:18:50f778e3737ad3ef79706bcf35f18d38dc068b7e1530b75d82a60315cb6e1443cbelfMirai
2025-10-13 05:34:251e32f52dc84d341a165fae5e310f86ccc5f9970c898659149218ec31b9640ed4elfMirai
2025-10-13 05:34:216c6df42a6934cf566583861f7870d55f1e09d46ece58396af6a81cf1b16ff881elfMirai
2025-10-13 05:34:20215ca8d287d9eb62a0823a4de5a6545d87453e41872f14bdd8047cab035831b1elfMirai
2025-10-13 05:34:2087d56ee88baea0191d2bec7a2abb41cb74b3f2f2b976a2e197f56d20f24a3e61elfMirai
2025-10-13 05:34:19870e33b473e851aed35095627204bd2ed7104812305361cf54df5e7b4d883d6bshMirai
2025-10-13 05:34:18e48469fdf3f1a8c1db70d059c6ed544a40cbae094f9b31e5fb885f254b27c1eeelfMirai
2025-10-13 05:34:1821e8420e2bce3849c7a769a7528c74f53a5add799606399b056f9090347ce6c4elfMirai
2025-10-13 05:34:14769c08447897057176f994fee999fdeee673535ffe3f1d639060a1fdff17bfb8elfMirai
2025-10-13 05:34:13138370145564ddb2b40f875b28a365134567f6865bbcecd08de5a782a3252128elfMirai
2025-10-13 05:34:1351ee1e61eac7a0dfdc1fd42ca93676cbe73f288e5e3c9d81509855d6d184845aelfMirai
2025-10-13 05:34:13e19458cf891d7e14ad4b0b6e8fa8fef6066daf953f1d795085fa7309d3c7949delfMirai
2025-10-13 05:34:13987c294af82c88d806e02abac01cb3f955533c4ea38c7fe664b84696d902f03aelfMirai
2025-10-13 05:34:12234c1476e7002c92f77d72c166719a9db67c677c13d31d7aef445f9565dcf5c8elfMirai