URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 196.251.115.82
Firstseen:2025-10-30 04:13:05 UTC
Total malware sites :31
Online malware sites :0 (0%)
Offline Malware sites :31 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-31 21:44:05http://196.251.115.82/1.shOfflinemirai ext opendir DaveLikesMalwre
2025-10-30 11:10:20http://196.251.115.82/bins/morte.spcOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 11:10:20http://196.251.115.82/bins/morte.arm5Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-30 11:10:20http://196.251.115.82/bins/morte.i686Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-30 09:54:21http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:21http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:20http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:20http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:20http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:20http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:20http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:07http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:07http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:07http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:07http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:07http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:06http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:06http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 09:54:05http://196.251.115.82/0010101010100101101010111...Offlineelf ua-wget abuse_ch
2025-10-30 04:13:23http://196.251.115.82/bins/morte.armOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:23http://196.251.115.82/bins/morte.arm7Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:23http://196.251.115.82/bins/morte.arcOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:23http://196.251.115.82/bins/morte.sh4Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:22http://196.251.115.82/bins/morte.x86_64Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:22http://196.251.115.82/bins/morte.mipsOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:22http://196.251.115.82/bins/morte.x86Offlineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:21http://196.251.115.82/bins/morte.m68kOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:21http://196.251.115.82/bins/debugOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:21http://196.251.115.82/bins/morte.ppcOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:11http://196.251.115.82/bins/morte.mpslOfflineelf mirai ext ua-wget ClearlyNotB
2025-10-30 04:13:10http://196.251.115.82/bins/morte.arm6Offlineelf mirai ext ua-wget ClearlyNotB

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-31 21:44:05e5dd7a348c932383634a924b78c8ac0cccb9c65ae4f921095e9958ef5b02eae9shMirai
2025-10-30 23:29:18c8ae7fee6b607a59a8a76bdf0026a987c118b01d7843cc01c3e4cd7182e67fd5elfMirai
2025-10-30 22:41:309d717775b3a0461cc62c5a8fbfd6027e62fb8f8ff47e5d1dc28a12db816cdcf3elfMirai
2025-10-30 18:06:52898f7f84f9ad51ae37a565893e4f72b6ebce2691d529f8744d7d3fb32ed4c4caelfMirai
2025-10-30 17:39:5763021604b19c822d162cb1ff2e65a49e51c792fecfb2975f068ab5acb805a04felfMirai
2025-10-30 12:52:548ba34509d086573760aa8f7677c3d828c0cf477bd4342a9f743c7ba9b81051f5elfMirai
2025-10-30 12:07:2054f3f6d1330b4c9667d1113ee3329c2a023cab9a71de20ba55dbed869a38a6b2elfMirai
2025-10-30 10:28:28f904c5dbb0f0346f55ca3667fbe2f97aaac07b320ae16e4fcf718c34f23de2cdelfMirai
2025-10-30 06:33:4378e298ff1f2564c9b55330ddf19507dae4b8ebe9e06e062fa3774f30d7286b81elfMirai
2025-10-30 05:44:04e98333b12e1353d142e9b467839d4f21a7640294f4b7cd9bd9a6029d93b806b3elfMirai
2025-10-30 05:31:586ceddf85002197439346890d29eda288c11ab7e11c27deb86a953bd96dd03096elfMirai
2025-10-30 05:18:51abb79091e35cd813de2d50e02ec355d6fc309d704ab8bc6d4354bbda531ca615elfMirai
2025-10-30 05:02:18224bb391451b00c3c44269f7d9d94caa59623c65e08e24de22420f4f21686440elfMirai
2025-10-30 04:37:50570791184ff5faa904839758cc51c3419e3802e8abe9d347e5928915e17d7ffeelfMirai
2025-10-30 04:13:10b5ff3d5b1158f4cb6bffa6e8a1a4c25af0ee8655c31b0b8084c50e2f913daa5celfMirai
2025-10-30 04:13:10c7121493e6e7e2c519dfaf688d1be09d07d06d46ac3984cc513d52d190169c9aelfMirai