URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 207.167.64.12
Firstseen:2025-08-15 06:48:05 UTC
Total malware sites :33
Online malware sites :0 (0%)
Offline Malware sites :33 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-15 06:48:11 207.167.64.12Not listedAS11169 ARQUENZO-KCMO-01- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-08-18 06:01:08http://207.167.64.12/bins2.shOfflinegafgyt ext geofenced sh ua-wget USA botnetkiller
2025-08-17 09:26:17http://207.167.64.12/arm.nnOfflineelf GorillaBotnet mirai ext ua-wget BlinkzSec
2025-08-17 09:25:18http://207.167.64.12/arm6.nnOfflineelf GorillaBotnet mirai ext ua-wget BlinkzSec
2025-08-17 09:25:18http://207.167.64.12/arm5.nnOfflineelf GorillaBotnet mirai ext ua-wget BlinkzSec
2025-08-17 09:10:24http://207.167.64.12/2.m68kOfflineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:24http://207.167.64.12/2.i586Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:20http://207.167.64.12/2.mipsOfflineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:19http://207.167.64.12/2.sh4Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:18http://207.167.64.12/2.ppcOfflineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:13http://207.167.64.12/2.sparcOfflineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:13http://207.167.64.12/2.arm7Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:13http://207.167.64.12/2.i686Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:12http://207.167.64.12/2.arm5Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:12http://207.167.64.12/2.mpslOfflineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:12http://207.167.64.12/2.arm6Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:11http://207.167.64.12/2.arm4Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-17 09:10:10http://207.167.64.12/2.x86Offlineelf gafgyt ext ua-wget abuse_ch
2025-08-16 13:51:40http://207.167.64.12/bins/flow.arm4Offlineelf ua-wget abuse_ch
2025-08-16 13:51:40http://207.167.64.12/bins/flow.x86_64Offlineelf ua-wget abuse_ch
2025-08-15 06:49:20http://207.167.64.12/bins/flow.sh4Offlinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:49:20http://207.167.64.12/bins/flow.x86Offlinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:49:17http://207.167.64.12/arm7.nnOfflinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:49:17http://207.167.64.12/bins.shOfflinecensys gafgyt ext mirai ext sh ua-wget NDA0E
2025-08-15 06:49:16http://207.167.64.12/bins/flow.m68kOfflinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/gOfflinecensys mirai ext sh ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.arm5Offlinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.mipsOfflinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.arm7Offlinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.mpslOfflinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.arm6Offlinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.spcOfflinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.armOfflinecensys elf mirai ext ua-wget NDA0E
2025-08-15 06:48:11http://207.167.64.12/bins/flow.ppcOfflinecensys elf mirai ext ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-08-18 07:36:27dbe0b127987330a7331c97199e8ac8171e01c1f66e62ef7309aef5e8bd7fc615shGafgyt
2025-08-18 02:02:2993192aadd5468cb6d84bed4221a032921c369daad6a30a9c5711d3d320968c0ashGafgyt
2025-08-17 12:05:1044f3b01c2fda8b4b157d200a32adaf833e8f3c36a3592d41d83149d3738febbcshMirai
2025-08-17 09:26:1786a77643ac33e490cf49512d223e3c9b167337875ea727751cb1560d1a1460e0elfMirai
2025-08-17 09:25:18f1590dbb7f242d7a8212a1108ced0b2feff991ba958b2109e826fa35b6f6fe70elfMirai
2025-08-17 09:25:1868a2d3abee5f7b71c5428ec744712d36c9a24f3a323fad4c4bb3b8cea2993b5aelfMirai
2025-08-17 09:10:24618b6921b8ab050ce00b3ae4f56decd6ea6c609b627c9ac62da1ca3d842f7f73elfGafgyt
2025-08-17 09:10:245612288ee73116ecf7178fd9fd98290352bdd8863178db3c3c07b4f742c19e67elfGafgyt
2025-08-17 09:10:20f758f794dbd3d35b0c4236269b1b78913596c18868e0a25848249248405fc9f8elfGafgyt
2025-08-17 09:10:192167d964e35b585812d66a293dcb24748ecf0c6ea2c8c64d40c0ece6dcfbdaacelfGafgyt
2025-08-17 09:10:18d28891a4b1871516cd07a57c125bc759492584ecb7ca43571dc26074bfeac8abelfGafgyt
2025-08-17 09:10:13c6b9d9efb681ff1ac0afe4b47103c519b68532bca79844f7e075e1ce999d74f8elfGafgyt
2025-08-17 09:10:1358baecf3698e6810dd5fa6ce4cdf478f699270634f4a132314da68fc3e08c88aelfGafgyt
2025-08-17 09:10:13dfa2f76c20c39fbdd9d97f90fd9241f0635b3a0be6c238b0e11715e75c9c63caelfGafgyt
2025-08-17 09:10:125d17d03d5f2ee245fc6cd1021d75913df3c959432b99d380e8a3638841062643elfGafgyt
2025-08-17 09:10:1272dbb20dccfd8bf3ba4e4b9d58a0d95de432e3e780a12f41bb171361e67776cdelfGafgyt
2025-08-17 09:10:12f7c5e707383ac0efb2b3383e45c8e66a2bd3c5e66eff7244b691ba65741de7b0elfGafgyt
2025-08-17 09:10:1014b8b6ac8a6d96e15edf83a71f042ca1b47128b8ba75439103eb88839f3eb898elfGafgyt
2025-08-17 09:10:10d71cd66700fc7e1c1f921bea1df0722cfd5ba411fb434e42323d83cbbd06c136elfGafgyt
2025-08-17 08:23:1139561994cc6b00679bc2dd1705b778e14c3bac6b6732e8167b94e6142e92625cshMirai
2025-08-15 06:49:200208a5de2be5d261010cc8d475702926b6441c0704cfef91c9d6fff0e9f831e6elfMirai
2025-08-15 06:49:20407585d915dfd478d210997600903649c80eafdb0ff89e6427c3232eb985eabaelfMirai
2025-08-15 06:49:177fa61d96545d9723646d109fa0303ea8c97adb12f411f3b44f49e178b7922d74elfMirai
2025-08-15 06:49:1765b040b1edd4c4d592c722725cd4d57e22aa5d26e762f926601bd17b3ac29444shMirai
2025-08-15 06:49:16ffa75d143387e91c79ff318dc116391d35698ace5b41bdbf5de810cbb99ab923elfMirai
2025-08-15 06:48:107312bfd94e4efbaefd2bca8a80de2998262873a5e63548243b7d3a5b8d1372d6shMirai
2025-08-15 06:48:10f6be0134987bbfb7c727939b5312383f863d9af11739acb3d3cb594bb733c48aelfMirai
2025-08-15 06:48:102f4baaa5ed764952485b2d4e510470a0982bbe2b4673c095ad3daea2eb8f631delfMirai
2025-08-15 06:48:105e4030d0afcda52db7f8f9523a1dcef9fc340900e3a009571ed6e2a121797e8delfMirai
2025-08-15 06:48:10abd7cb42168dcd234a920c326f8988f9a9058c5cff548509f8be4d29b669ba76elfMirai
2025-08-15 06:48:1026e3c095af347e794e9faa0ad67c4aeddae75b2d9109b3e70435b4e91d131875elfMirai
2025-08-15 06:48:100527fbf5694db013c808451fd46d95e8db18f892d205323a2ef77a7fa9664a2felfMirai
2025-08-15 06:48:107457bc7f31345875644d55a9284816fd6e4c5e0ea5368b7fbba61da9dc46bc51elfMirai
2025-08-15 06:48:10dceb73de437137e751a85f1fc6f6549071e886d60e1eeaa0c60fc44d37a632ffelfMirai