URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 204.76.203.6
Firstseen:2022-06-30 20:21:03 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-06-30 20:21:05 204.76.203.6SBL673234AS51396 PFCLOUD- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-06 10:59:05http://204.76.203.6//gigasex.x86Offlineddos elf mirai ext Gandylyan1
2022-10-04 22:15:05http://204.76.203.6/gigasex.sparcOfflineelf gafgyt ext mirai ext r3dbU7z
2022-10-04 22:07:05http://204.76.203.6/gigasex.ppcOfflineelf mirai ext r3dbU7z
2022-10-04 22:07:05http://204.76.203.6/gigasex.sh4Offlineelf mirai ext r3dbU7z
2022-10-04 22:07:05http://204.76.203.6/gigasex.mpslOfflineelf mirai ext r3dbU7z
2022-10-04 22:07:05http://204.76.203.6/gigasex.i686Offlineelf gafgyt ext mirai ext r3dbU7z
2022-10-04 22:07:05http://204.76.203.6/gigasex.m68kOfflineelf mirai ext r3dbU7z
2022-10-04 22:07:05http://204.76.203.6/gigasex.mipsOfflineelf mirai ext r3dbU7z
2022-10-04 22:06:04http://204.76.203.6/gigasex.arm4Offlineelf gafgyt ext mirai ext r3dbU7z
2022-10-04 22:06:04http://204.76.203.6/gigasex.arm7Offlineelf gafgyt ext mirai ext r3dbU7z
2022-10-04 22:06:04http://204.76.203.6/gigasex.arm6Offlineelf gafgyt ext mirai ext r3dbU7z
2022-10-04 22:06:04http://204.76.203.6/gigasex.arm5Offlineelf mirai ext r3dbU7z
2022-10-04 22:06:04http://204.76.203.6/gigasex.i586Offlineelf mirai ext r3dbU7z
2022-06-30 20:21:05http://204.76.203.6/bins/ZG9zx86Offlineddos mirai ext Gandylyan1
2022-06-30 20:21:05http://204.76.203.6/bins/ZG9zarmOfflineddos mirai ext Gandylyan1
2022-06-30 20:21:05http://204.76.203.6/bins/ZG9zmpslOfflineddos mirai ext Gandylyan1
2022-06-30 20:21:05http://204.76.203.6/bins/ZG9zarm5Offlineddos mirai ext Gandylyan1
2022-06-30 20:21:05http://204.76.203.6/bins/ZG9zmipsOfflineddos mirai ext Gandylyan1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-10-06 10:59:058e44dbc5a58f8c509c858b7bcf9123669773e316bdeaf32ee84d9e40d9881f71elfMirai
2022-10-04 22:15:05017f4cfa1837951a10bd1c1ae0a05be290964c40bd4e569dbd78ae2d335a1342elfMirai
2022-10-04 22:07:054959d5f656ea93d015ae61cdbbca6069e6bf014bca828f1ce73d5d717218c527elfMirai
2022-10-04 22:07:058e3ab0350c8337783c5856336dd303b2fb6de032e885e342883c15d84db94943elfMirai
2022-10-04 22:07:054ebaffca0ed347c84e2b310d6019598308f215b5360cdd100c74c642a5c4d515elfMirai
2022-10-04 22:07:058819400bb15addb722407fa4849a49a7c1d799dba860ae9f5c61ae7ab5920da6elfGafgyt
2022-10-04 22:07:05467baea36295bfded4940129dafb455ebf1b79e3e24b057ae3ad452823192f2belf  
2022-10-04 22:07:058cd3473c6b026bb780d5d2e7e290708f5236f91721850e93958c16a146b9fe0aelf  
2022-10-04 22:06:0409f48444f993973e4d8a3afc83063f1c60d4ecab52eaec5bd0daa489285e9b78elfGafgyt
2022-10-04 22:06:04a66b08149f43d12d8b891eb12e6e3ccdf092e6f04200a36916828fba9eed47f3elfGafgyt
2022-10-04 22:06:04d4179d3b7cc3752769dcb5b8edee983bf5063c8028ed5a2678bc4050e5ee1077elfGafgyt
2022-10-04 22:06:04274001347b5da27fece39d535c1028e0b9742c6c60f697fe24f77c9cd4820703elf  
2022-10-04 22:06:04c45b35da53e4458a5f91bd22c50af5cea9fc70bc448d5172d529c1bd6da34d45elfMirai
2022-06-30 20:21:05f0efa3f87c423be7b37a345bf1400a09ef78c822e99233af06e3601e65f06e8aelfMirai
2022-06-30 20:21:054485068a5b079e206e3691a72d3c6cdba7c14ee9d69bb466e00fc6dd60c2087eelfMirai
2022-06-30 20:21:05898a92a6c7ab07b51f49f3dae8c7a3a8d5d8ffc25b21bfcba75675be2d72ec5delf  
2022-06-30 20:21:04fd6e38712e5918353230f4c1d9d6d17e135b68b9f15754f30f741a92b115c323elf  
2022-06-30 20:21:042d6b9635a453f64e860fd57b3bd3960207b2d4a0928a1d03d4a78dc059f333ebelf