URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 20.151.71.228
Firstseen:2023-03-26 23:20:06 UTC
Total malware sites :11
Online malware sites :0 (0%)
Offline Malware sites :11 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-03-26 23:20:21 20.151.71.228Not listedAS8075 MICROSOFT-CORP-MSN-AS-BLOCK- CAyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-03-26 23:21:18http://20.151.71.228/shOffline32 elf sparc Tsunami ext zbetcheckin
2023-03-26 23:21:18http://20.151.71.228/sshdOffline32 elf mips Tsunami ext zbetcheckin
2023-03-26 23:21:18http://20.151.71.228/pftpOffline32 elf motorola Tsunami ext zbetcheckin
2023-03-26 23:21:18http://20.151.71.228/bashOffline64 elf Tsunami ext zbetcheckin
2023-03-26 23:21:03http://20.151.71.228/bins.shOfflineshellscript zbetcheckin
2023-03-26 23:20:22http://20.151.71.228/apache2Offline32 arm elf Tsunami ext zbetcheckin
2023-03-26 23:20:22http://20.151.71.228/ntpdOffline32 elf mips Tsunami ext zbetcheckin
2023-03-26 23:20:21http://20.151.71.228/tftpOffline32 arm elf Tsunami ext zbetcheckin
2023-03-26 23:20:21http://20.151.71.228/wgetOffline32 elf intel Tsunami ext zbetcheckin
2023-03-26 23:20:21http://20.151.71.228/cronOffline32 elf PowerPC Tsunami ext zbetcheckin
2023-03-26 23:20:21http://20.151.71.228/ftpOffline32 elf intel Tsunami ext zbetcheckin