URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 206.189.22.92
Firstseen:2026-03-28 06:46:04 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-28 06:46:04 206.189.22.92Not listedAS14061 DIGITALOCEAN-ASN- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-29 14:00:13http://206.189.22.92/1.shOfflinemirai ext script geenensp
2026-03-29 14:00:10http://206.189.22.92/windyloveyou/windy.mipsOfflinemirai ext GAYINT_DOT_ORG
2026-03-29 14:00:10http://206.189.22.92/windyloveyou/windy.arcOfflinemirai ext GAYINT_DOT_ORG
2026-03-29 14:00:10http://206.189.22.92/windyloveyou/windy.x86Offlinemirai ext GAYINT_DOT_ORG
2026-03-29 14:00:08http://206.189.22.92/windyloveyou/windy.i468Offline GAYINT_DOT_ORG
2026-03-28 06:46:04http://206.189.22.92/all.shOfflinescript geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-29 14:00:12c78e6c73ac9a847b19d1015375ab4a3ee54ea4fffcb51acf07551cffb4b55698shMirai
2026-03-29 14:00:10a02a0f252be3169d001a06edf82cbef1e42eb8563ce008c6494a86802600598celfMirai
2026-03-29 14:00:092babebf57645fdf53226c5b91a2a512217ed7e993fc7925fcb2ec6f14664452delfMirai
2026-03-29 14:00:090b3ccfd50900c6a377e91d4d3628e6f41d9934cbb2753ac01f546c6a4f33e170elfMirai