URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 211.237.120.13
Firstseen:2021-01-11 15:34:25 UTC
Total malware sites :34
Online malware sites :0 (0%)
Offline Malware sites :34 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-10-17 04:52:10 211.237.120.13Not listedAS10036 CNM-AS-KR- KRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-06-23 17:24:07http://211.237.120.13:3183/iOffline32-bit elf mips Mozi ext geenensp
2023-06-23 17:02:09http://211.237.120.13:3183/bin.shOffline32-bit elf mips Mozi ext geenensp
2023-06-22 11:20:11http://211.237.120.13:3183/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2023-06-05 17:20:24http://211.237.120.13:2985/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2023-05-29 20:19:21http://211.237.120.13:2985/iOffline32-bit elf mips Mozi ext geenensp
2023-05-29 20:00:14http://211.237.120.13:2985/bin.shOffline32-bit elf mips Mozi ext geenensp
2023-05-26 11:14:16http://211.237.120.13:4474/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2023-05-18 22:28:20http://211.237.120.13:4474/iOffline32-bit elf mips Mozi ext geenensp
2023-04-27 19:19:20http://211.237.120.13:4474/bin.shOffline32-bit elf mips Mozi ext geenensp
2022-12-08 19:52:06http://211.237.120.13:2302/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2022-08-28 11:43:05http://211.237.120.13:2302/iOffline32-bit elf mips Mozi ext geenensp
2022-08-28 11:16:08http://211.237.120.13:2302/bin.shOffline32-bit elf mips Mozi ext geenensp
2022-08-24 23:35:07http://211.237.120.13:2302/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2022-08-17 12:04:06http://211.237.120.13:2555/Mozi.mOfflineMozi ext Gandylyan1
2022-06-15 00:30:06http://211.237.120.13:2265/mozi.mOffline tammeto
2022-06-04 03:00:07http://211.237.120.13:2265/iOffline32-bit elf mips Mozi ext geenensp
2022-06-04 02:30:08http://211.237.120.13:2265/bin.shOffline32-bit elf mips Mozi ext geenensp
2022-05-23 10:21:06http://211.237.120.13:4434/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2022-05-22 12:34:08http://211.237.120.13:4434/iOffline32-bit elf mips Mozi ext geenensp
2022-05-22 12:00:07http://211.237.120.13:4434/bin.shOffline32-bit elf mips Mozi ext geenensp
2022-05-20 22:20:07http://211.237.120.13:4292/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2022-05-06 03:00:07http://211.237.120.13:4399/bin.shOffline32-bit elf mips Mozi ext geenensp
2022-04-26 15:29:07http://211.237.120.13:4399/iOffline32-bit elf mips Mozi ext geenensp
2022-04-25 02:20:06http://211.237.120.13:4399/Mozi.aOfflineelf Mozi ext lrz_urlhaus
2022-04-08 19:51:08http://211.237.120.13:4399/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-12-21 04:05:06http://211.237.120.13:2938/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-12-10 15:24:05http://211.237.120.13:2938/iOffline32-bit elf mips geenensp
2020-12-10 15:13:05http://211.237.120.13:2938/bin.shOffline32-bit elf mips geenensp
2020-11-07 20:21:06http://211.237.120.13:2326/Mozi.mOfflineelf Mozi ext lrz_urlhaus
2020-11-02 03:35:07http://211.237.120.13:2326/iOffline32-bit elf mips geenensp
2020-11-02 03:08:06http://211.237.120.13:2326/bin.shOffline32-bit elf mips geenensp
2020-10-23 10:27:05http://211.237.120.13:4477/iOffline32-bit elf mips geenensp
2020-10-23 09:53:06http://211.237.120.13:4477/bin.shOffline32-bit elf mips geenensp
2020-10-17 04:52:10http://211.237.120.13:4330/Mozi.mOfflineelf Mozi ext lrz_urlhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-06-23 17:24:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-06-23 17:02:08f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-06-22 11:20:11f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-06-05 17:20:24f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-29 20:19:21f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-29 20:00:14f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-26 11:14:16f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-05-18 22:28:20f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2023-04-27 19:19:20f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-12-08 19:52:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-08-28 11:43:05f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-08-28 11:16:08f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-08-24 23:35:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-08-17 12:04:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-06-15 00:30:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-06-04 03:00:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-06-04 02:30:08f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-05-23 10:21:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-05-22 12:34:08f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-05-22 12:00:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-05-20 22:20:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-05-06 03:00:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-04-26 15:29:07f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-04-25 02:20:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2022-04-08 19:51:08f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2020-12-21 04:05:06f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2020-12-10 15:24:05f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2020-12-10 15:13:05f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8elf 
2020-11-07 20:21:06798725bcb7292e8b41279521dde20eea17c119e8a37c39dea098091a210f611celf  
2020-11-02 03:35:07798725bcb7292e8b41279521dde20eea17c119e8a37c39dea098091a210f611celf  
2020-11-02 03:08:06798725bcb7292e8b41279521dde20eea17c119e8a37c39dea098091a210f611celf  
2020-10-23 10:27:05798725bcb7292e8b41279521dde20eea17c119e8a37c39dea098091a210f611celf  
2020-10-23 09:53:06798725bcb7292e8b41279521dde20eea17c119e8a37c39dea098091a210f611celf  
2020-10-17 04:52:09798725bcb7292e8b41279521dde20eea17c119e8a37c39dea098091a210f611celf