URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 202.67.98.13
Firstseen:2020-09-15 07:35:16 UTC
Total malware sites :20
Online malware sites :0 (0%)
Offline Malware sites :20 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-09-15 07:35:21 202.67.98.1313.98-67-202.dart.iprimus.net.auNot listedAS9443 VOCUS-RETAIL-AU- AUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-11-22 11:55:07http://202.67.98.13:34288/bin.shOffline32-bit elf mips geenensp
2020-11-19 20:20:07http://202.67.98.13:34288/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-11-09 11:58:10http://202.67.98.13:40227/iOffline32-bit elf mips geenensp
2020-11-04 08:07:06http://202.67.98.13:40227/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-10-06 17:51:33http://202.67.98.13:53551/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-10-05 19:04:33http://202.67.98.13:53551/iOffline32-bit elf mips geenensp
2020-10-05 11:59:32http://202.67.98.13:53551/bin.shOffline32-bit elf mips geenensp
2020-10-03 13:39:06http://202.67.98.13:52552/iOffline32-bit elf mips geenensp
2020-09-28 14:21:06http://202.67.98.13:40575/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-09-23 07:54:08http://202.67.98.13:55405/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-09-23 04:45:07http://202.67.98.13:55405/iOffline32-bit elf mips geenensp
2020-09-23 04:02:08http://202.67.98.13:55405/bin.shOffline32-bit elf mips geenensp
2020-09-22 09:32:11http://202.67.98.13:37898/iOffline32-bit elf mips geenensp
2020-09-22 06:38:19http://202.67.98.13:37898/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2020-09-18 15:05:12http://202.67.98.13:52458/iOffline32-bit elf mips geenensp
2020-09-18 14:53:06http://202.67.98.13:52458/bin.shOffline32-bit elf mips geenensp
2020-09-17 17:21:06http://202.67.98.13:52458/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-09-15 22:39:11http://202.67.98.13:44413/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-09-15 10:54:31http://202.67.98.13:44413/iOffline32-bit elf mips geenensp
2020-09-15 07:35:21http://202.67.98.13:44413/bin.shOffline32-bit elf mips geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-11-22 11:55:07b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-11-19 20:20:07b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-11-09 11:58:10b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-11-04 08:07:06b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-10-06 18:17:43b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-10-05 19:14:01b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-10-05 12:30:07b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-10-03 13:39:06b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605elf  
2020-09-28 14:21:06c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-23 07:54:082e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6elf  
2020-09-23 04:45:072e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6elf  
2020-09-23 04:02:082e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6elf  
2020-09-22 09:32:11c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-22 06:38:19c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-18 15:05:12c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-18 14:53:06c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-17 17:21:06c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-15 22:39:11c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-15 10:54:31c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf 
2020-09-15 07:35:21c672798dca67f796972b42ad0c89e25d589d2e70eb41892d26adbb6a79f63887elf