URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 196.251.114.199
Firstseen:2025-10-31 07:03:04 UTC
Total malware sites :30
Online malware sites :0 (0%)
Offline Malware sites :30 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-04 07:40:26http://196.251.114.199/bins/pi586Offlineelf ua-wget abuse_ch
2025-11-04 07:40:26http://196.251.114.199/bins/m68kOfflineelf ua-wget abuse_ch
2025-11-04 07:40:26http://196.251.114.199/bins/ppcOfflineelf ua-wget abuse_ch
2025-11-04 07:40:25http://196.251.114.199/bins/arm7Offlineelf ua-wget abuse_ch
2025-11-04 07:40:25http://196.251.114.199/bins/arm5Offlineelf ua-wget abuse_ch
2025-11-04 07:40:25http://196.251.114.199/bins/arm4Offlineelf ua-wget abuse_ch
2025-11-04 07:40:25http://196.251.114.199/bins/mpslOfflineelf ua-wget abuse_ch
2025-11-04 07:40:14http://196.251.114.199/bins/pppcOfflineelf mirai ext ua-wget abuse_ch
2025-11-04 07:40:14http://196.251.114.199/bins/px86_64Offlineelf ua-wget abuse_ch
2025-11-04 07:40:13http://196.251.114.199/bins/arm6Offlineelf ua-wget abuse_ch
2025-11-04 07:40:13http://196.251.114.199/bins/sh4Offlineelf ua-wget abuse_ch
2025-11-04 07:40:13http://196.251.114.199/bins/x86Offlineelf ua-wget abuse_ch
2025-11-04 07:40:13http://196.251.114.199/bins/mipsOfflineelf ua-wget abuse_ch
2025-11-04 06:39:24http://196.251.114.199/kla.shOfflinesh BlinkzSec
2025-11-04 06:39:23http://196.251.114.199/c.shOfflinemirai ext sh BlinkzSec
2025-11-04 06:38:26http://196.251.114.199/binOfflinesh BlinkzSec
2025-11-04 06:38:25http://196.251.114.199/wget.shOfflinemirai ext sh BlinkzSec
2025-11-04 06:38:14http://196.251.114.199/w.shOfflinemirai ext sh BlinkzSec
2025-11-04 06:38:14http://196.251.114.199/yarnOfflinesh BlinkzSec
2025-11-04 06:38:14http://196.251.114.199/payOfflinesh BlinkzSec
2025-10-31 07:03:25http://196.251.114.199/bins/parm5Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:25http://196.251.114.199/bins/pmpslOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:20http://196.251.114.199/bins/parm7Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:20http://196.251.114.199/bins/pm68kOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:19http://196.251.114.199/bins/px86Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:19http://196.251.114.199/bins/parmOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:11http://196.251.114.199/bins/pspcOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:08http://196.251.114.199/bins/pmipsOfflineDEU elf geofenced mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:07http://196.251.114.199/bins/psh4Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-31 07:03:06http://196.251.114.199/bins/parm6Offlineelf mirai ext ua-wget ClearlyNotB

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-04 09:07:33e89aacf39f962a3fbd203ed408b475d3f9ac985ab23ce3489d0dc98fcceaeb37shMirai
2025-11-04 08:40:40e89aacf39f962a3fbd203ed408b475d3f9ac985ab23ce3489d0dc98fcceaeb37shMirai
2025-11-04 07:49:107a5ccea5287eeba3412d97c3ad509535d9a591b7c99ba0ce1930dcfcbfc16f61sh 
2025-11-04 07:40:14d51e3825c28a858d438229bd88050835e090f1923b1935fb321d9d5790828653elfMirai
2025-11-04 07:15:157a5ccea5287eeba3412d97c3ad509535d9a591b7c99ba0ce1930dcfcbfc16f61sh 
2025-11-04 06:38:147a5ccea5287eeba3412d97c3ad509535d9a591b7c99ba0ce1930dcfcbfc16f61sh 
2025-11-04 06:38:147a5ccea5287eeba3412d97c3ad509535d9a591b7c99ba0ce1930dcfcbfc16f61sh 
2025-11-04 06:38:14f6c0e81a211d47beac6c201fa8024d4cf1423df035335c7706ffc7fa9115c5c6shMirai
2025-10-31 09:33:27bbbc704e34bebf1947d288a63c9c2ff39a2975983cc66358d5b4c2c2b250fe57elfMirai
2025-10-31 09:23:46c643a81227e300f1e7737358b04f70039f272a36c5932161768be025be8095fdelfMirai
2025-10-31 09:13:56f03f0c9bcf169e716260f28ff60671acbdfc32902c24390691fd605914a67e05elfMirai
2025-10-31 08:38:466daf093180aa5eed5e2e3c57d4cd08bf4256b9da14f3ca34c8e36d88ab18db2celfMirai
2025-10-31 08:14:186d5c885a939844849dd324987efdd55f9de3693dd660ff401810035f495ed529elfMirai
2025-10-31 07:53:41f7b0e8d4f6113c9b109adc25b0430e0a2659dc5abd6e004e27856e29f2ce0a51elfMirai
2025-10-31 07:03:11909cf78a489fcf08e7f69c4593ef2cb304f5a2f66dc1854d9f5d93b6b83b1610elfMirai
2025-10-31 07:03:0806bb8b785aea7cb2988f7ac7e29d31bfa1a65355740dd0933a7e8b6633a1c97aelfMirai
2025-10-31 07:03:07562eae54a314f565b875a5f6c1869a7992011c2c9dbf97e79252890e0476cd6eelfMirai
2025-10-31 07:03:064a307a10ee486cace2a73f2c9c121e0ea40af6bd9d28f569f703f8a49856114celfMirai