URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 196.251.69.157
Firstseen:2025-04-17 14:16:02 UTC
Total malware sites :14
Online malware sites :0 (0%)
Offline Malware sites :14 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-18 05:16:03http://196.251.69.157/cronOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/wgetOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/apache2Offlineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/shOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/ftpOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/nutOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/sshdOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/pftpOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/bashOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/telnetdOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/opensshOfflineelf ua-wget abuse_ch
2025-04-18 05:16:03http://196.251.69.157/ntpdOfflineelf ua-wget abuse_ch
2025-04-17 14:29:04http://196.251.69.157/bins.shOfflinegafgyt ext sh NDA0E
2025-04-17 14:16:05http://196.251.69.157/tftpOfflineelf gafgyt ext NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-04-17 14:29:04ff5b53d7f961512056919faa36075109dae2b1859011a179444657d33c7226beshGafgyt
2025-04-17 14:16:04221b2b8ec945324c54d467df7fbeb4d7a8eb97e20c3a2a2dd0a9b09c599e0cfdelfGafgyt