URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 202.61.139.34
Firstseen:2025-09-27 21:16:04 UTC
Total malware sites :50
Online malware sites :12 (24%)
Offline Malware sites :38 (76%)
Newest active malware site :2026-01-15 18:05:07 UTC
Oldest active malware site :2026-01-15 18:03:06 UTC (Age: 7 hours, 38 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-09-27 21:16:22 202.61.139.34SBL669380AS152194 CTGSERVERLIMITED-AS-AP- SGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-15 18:05:07http://202.61.139.34:65532/webshell.warOnlinehuntio opendir ua-wget BlinkzSec
2026-01-15 18:04:15http://202.61.139.34:65532/dbs/linux.shOfflinehuntio opendir sh ua-wget BlinkzSec
2026-01-15 18:03:18http://202.61.139.34:65532/linux_mipselOnlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:14http://202.61.139.34:65532/linux_amd64Onlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:14http://202.61.139.34:65532/linux_arm7Onlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:14http://202.61.139.34:65532/linux_arm5Onlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:14http://202.61.139.34:65532/linux_mips64elOnlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:14http://202.61.139.34:65532/linux_arm6Onlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:14http://202.61.139.34:65532/linux_mips64Onlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:14http://202.61.139.34:65532/linux_aarch64Onlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:12http://202.61.139.34:65532/linux_386Onlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:07http://202.61.139.34:65532/linux_mipsOnlinehuntio Kaiji opendir ua-wget BlinkzSec
2026-01-15 18:03:06http://202.61.139.34:65532/xxaOnlinehuntio opendir ua-wget BlinkzSec
2025-09-28 13:50:23http://202.61.139.34:65120/win.exeOfflineChaos exe opendir botnetkiller
2025-09-28 13:50:13http://202.61.139.34:65120/download.shOfflinegeofenced opendir sh ua-wget USA botnetkiller
2025-09-28 13:46:42http://202.61.139.34:65120/linux_mips64Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:42http://202.61.139.34:65120/linux_mips64_softfloatOfflineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:42http://202.61.139.34:65120/linux_mipsel_softfloatOfflineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:42http://202.61.139.34:65120/linux_ppc64Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:42http://202.61.139.34:65120/linux_mipselOfflineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:42http://202.61.139.34:65120/linux_arm5Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:42http://202.61.139.34:65120/linux_arm64Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_mips_softfloatOfflineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_mipsOfflineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_ppc64elOfflineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_arm6Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_arm7Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_386Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_amd64Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_mips64el_softf...Offlineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 13:46:41http://202.61.139.34:65120/linux_mips64elOfflineelf geofenced Kaiji opendir ua-wget USA botnetkiller
2025-09-28 06:32:12http://202.61.139.34:65512/win.exeOfflineexe opendir botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_mips64el_softf...Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_mips64elOfflineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_arm5Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_amd64Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/download.shOfflinegeofenced opendir sh ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_mipsOfflineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_ppc64Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_arm6Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_386Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_mips64_softfloatOfflineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_mipsel_softfloatOfflineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_arm7Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_ppc64elOfflineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:09http://202.61.139.34:65512/linux_mipselOfflineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:08http://202.61.139.34:65512/linux_mips64Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:08http://202.61.139.34:65512/linux_arm64Offlineelf geofenced opendir ua-wget USA botnetkiller
2025-09-28 06:32:08http://202.61.139.34:65512/linux_mips_softfloatOfflineelf geofenced opendir ua-wget USA botnetkiller
2025-09-27 21:16:22http://202.61.139.34:65512/bin.x86Offline64-bit elf Kaiji x86-64 geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-15 18:05:077df18dab85d09ddfd38e71fbb8237e2601117983b589e00355df9520fb49191aunknown  
2026-01-15 18:03:18c7c98a5ba966a7ff410bee89fcb3c3f4088c17dc4b1dc0ec5382407b7c4e1f41elfKaiji
2026-01-15 18:03:144a97b1c545ae2f9f5e3b5aad2db93a763aaeed9678ef6fbf3d5149f912a31e93elfKaiji
2026-01-15 18:03:143d028580601e9b614ed5074741ad0756c9c383e353924c3a023dd78e867e7f92elfKaiji
2026-01-15 18:03:14cb37d6a32f360d1e79907595a2b0d00916cb3e7e306dc320711b3e0019d991d6elfKaiji
2026-01-15 18:03:1412f65318aa3316ad18c0a9e879f1171fbcfee23d4717e5925a12867e42b9f589elfKaiji
2026-01-15 18:03:144134fb3554e6dfa82d4822886968f50a008bb66b46f54f3a28dfd0ce167b1283elfKaiji
2026-01-15 18:03:14eaf2f72b30f65be112e05c6ab5d4cd3df59155b97ac4f2e8f4bc589e966ae6c3elfKaiji
2026-01-15 18:03:13d77b6eeb506ebd49b1f348eafd01f545cf41df13641a7417bcd8f34bdaa239d6elfKaiji
2026-01-15 18:03:1208b1ca7ff461d7931cdcbdeb71a22fd67bde07b93607bf2574b7cd666a93ed30elfKaiji
2026-01-15 18:03:07ab4525f80ffbdc65f127760d94ce05b9296a6c62f63f62ff6fac1a922a0a1a21elfKaiji
2026-01-15 18:03:061d971ecb535f66b367264556aa031706ec71504e60258d4d35640ade33bcf170elf 
2025-10-02 03:55:18eaf2f72b30f65be112e05c6ab5d4cd3df59155b97ac4f2e8f4bc589e966ae6c3elfKaiji
2025-09-28 14:06:3608310988e36012cabcfbb00d1aa0790117ff5f6d60572d974a452acb3ad2b400txt  
2025-09-28 13:50:2319b2d144baa5343de7ffad9d60724b7af4dc612e2e456c7a85382adfb4f24e54exeRansomware.Chaos
2025-09-28 13:46:426cb332c4248a7e6fdbffd4c36e3afa3f93a561f0f4836b5af9cfead5abd83cadelfKaiji
2025-09-28 13:46:426cb332c4248a7e6fdbffd4c36e3afa3f93a561f0f4836b5af9cfead5abd83cadelfKaiji
2025-09-28 13:46:42b06221aab526dfe8fb1b5233cbc62d6aa5b253c3f9aa2d7bceed8641405a4e06elfKaiji
2025-09-28 13:46:42b760ca2501fce0675753455ba5bf36f4518b253ee6617a2b28ad6f9c0adefcf9elfKaiji
2025-09-28 13:46:4259d04334276a73bffdc8108362512e816b98991c8f2d66468fb2b7448dd46aa1elfKaiji
2025-09-28 13:46:429f9a1a829a4e61207cf6358d1c7fd9055204840a7be07ea6844d2aaf7913db6delfKaiji
2025-09-28 13:46:410f126026a9a676a84ba2b93f152d7646626ad4b8e984025969bbd5c60a274775elfKaiji
2025-09-28 13:46:411c1046e173b4584a76869f3d9132dbb034acecda3837b23781f09c2678787a11elfKaiji
2025-09-28 13:46:41a039d85be5679970d2af85f662c5018f6b51e47d0a7fc146d16d72cd525692adelfKaiji
2025-09-28 13:46:414c93ed6a555c9202b0ff263607a1c39d8e2abe211c57b5f9d4acc80c9dc285c1elfKaiji
2025-09-28 13:46:4100adc960a4c5b25828f84d45e8225c08e66cb9315cb745702b3007e1f7bb1a80elfKaiji
2025-09-28 13:46:415079d694a0165fa0ffe864e00bc63619e4a77eaeb9652cf63a89dfee59887abdelfKaiji
2025-09-28 13:46:418a9d002bbce07fd74f8f9bba8196f84c348b30d2c1b965cdddbc1f8bee359790elfKaiji
2025-09-28 13:46:41fb58552f2e41f83d38518142997eab68d9f1068b597ad43549ab44f9b2621af5elfKaiji
2025-09-28 13:46:416b2d4b72f1e5302f8db2683de4c2406c1057d74c2412fba669e4c5dbfd14c198elfKaiji
2025-09-28 13:46:416b2d4b72f1e5302f8db2683de4c2406c1057d74c2412fba669e4c5dbfd14c198elfKaiji
2025-09-27 21:16:21fb58552f2e41f83d38518142997eab68d9f1068b597ad43549ab44f9b2621af5elfKaiji