URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.252.183.116
Firstseen:2024-01-19 07:02:05 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-01-19 07:02:07 192.252.183.116SBL655316AS152194 CTGSERVERLIMITED-AS-AP- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-01-19 07:02:11http://192.252.183.116:8089/u/123/100123/202401...OfflineCoinMiner Ivanti mirai ext RCE abuse_ch
2024-01-19 07:02:07http://192.252.183.116:8089/u/123/100123/202401...OfflineCoinMiner Ivanti RCE abuse_ch
2024-01-19 07:02:07http://192.252.183.116:8089/u/123/100123/202401...OfflineCoinMiner Ivanti RCE abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-01-19 07:02:1139ead6055306739ab969a3531bde2050f556b05e500894b3cda120178f2773beelfMirai
2024-01-19 07:02:074cba272d83f6ff353eb05e117a1057699200a996d483ca56fa189e9eaa6bb56cunknown  
2024-01-19 07:02:0745c9578bbceb2ce2b0f10133d2f3f708e78c8b7eb3c52ad69d686e822f9aa65fjson