URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 212.18.104.182
Firstseen:2025-04-25 11:50:03 UTC
Total malware sites :25
Online malware sites :0 (0%)
Offline Malware sites :25 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-25 11:50:05 212.18.104.18251758.ip-ptr.techNot listedAS215540 GCS-AS- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-04-25 12:19:09http://212.18.104.182/gompslOfflineelf geofenced ua-wget USA NDA0E
2025-04-25 12:19:09http://212.18.104.182/x86Offlineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/sshOfflinegeofenced sh ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/harm4Offlineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/ppcOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/sh4Offlineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/arm6Offlineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/nshkmpslOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/gmpslOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/hmipsOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/garm7Offlineelf geofenced ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/nshkmipsOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:08http://212.18.104.182/gmipsOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:07http://212.18.104.182/massloadOfflinegeofenced mirai ext sh ua-wget USA NDA0E
2025-04-25 12:19:07http://212.18.104.182/wget.shOfflinegeofenced mirai ext sh ua-wget USA NDA0E
2025-04-25 12:19:07http://212.18.104.182/tplink.shOfflinegeofenced mirai ext sh ua-wget USA NDA0E
2025-04-25 12:19:07http://212.18.104.182/spcOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 12:19:04http://212.18.104.182/tftp.shOfflinegeofenced sh ua-wget USA NDA0E
2025-04-25 11:54:06http://212.18.104.182/arm4Offlineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 11:54:05http://212.18.104.182/arm5Offlineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 11:54:05http://212.18.104.182/mpslOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 11:54:05http://212.18.104.182/mipsOfflineelf geofenced mirai ext ua-wget USA NDA0E
2025-04-25 11:54:03http://212.18.104.182/ftpget.shOfflinegeofenced sh ua-wget USA NDA0E
2025-04-25 11:53:19http://212.18.104.182/curl.shOfflinegeofenced sh ua-wget USA NDA0E
2025-04-25 11:50:05http://212.18.104.182/arm7Offlineelf geofenced mirai ext ua-wget USA NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-04-25 13:42:58d89014f6161f9de1f96ca2e6c832896c8ecdf6a4e9488f555c1a8d7e4ccbd9f2elfMirai
2025-04-25 13:22:1152500fe5bbd8a4a210012e4d9cb5198300ee72dd0ba74cc6fa506cd0b8529fabelf 
2025-04-25 13:05:3648435dbe00dc88d447da49eff2d7bd8964cc68b0f38bdc82e99539abc6812d37elfMirai
2025-04-25 12:19:094942ccaeed175c46d5863c62c62f7564afe33b8e71cd4f2cab00aebcdd2e16a8elf 
2025-04-25 12:19:09fac1336c367ff4de8553de906943579d02fad4203b13f1e2320d9d2a3dbce2b2elfMirai
2025-04-25 12:19:0852500fe5bbd8a4a210012e4d9cb5198300ee72dd0ba74cc6fa506cd0b8529fabelf 
2025-04-25 12:19:08b6290f746e1ed0a81595231f7e35ee800498ca297bfa6a2792fea13f8ef115f2elfMirai
2025-04-25 12:19:080fb348a94d09bf87933db195dabab709ce0575f993e98f21dd671b1672e88368elfMirai
2025-04-25 12:19:084d452c4e5d44b93d1b58fab021c792f49de027d6cbb892e221a7a0fae65f1c7delfMirai
2025-04-25 12:19:082e1a5de8bfb638992290a97c176243e9f8b5885f3f0c49bb8ce12e68587bdb86elfMirai
2025-04-25 12:19:08c04793bc372f59b6a075d97c6580b632bec7adb0baacfa76cae6dc02e1fde4b1elfMirai
2025-04-25 12:19:08d7029d2274187f09707babdc81c58a8e67ac94bc6fa51f654feee3ba3a036bedelfMirai
2025-04-25 12:19:0881212a277fc7311b584de15d58492403bf2453ead4fa33ca87a207b40970907felfMirai
2025-04-25 12:19:08634a07a67974b15543ae20182f856f17e33af25765a47bbce1c57c5153009f02elfMirai
2025-04-25 12:19:0883936c927f079f905572c5c4a004a24a74247ad2b0c47cfb211556244b4d3a8celfMirai
2025-04-25 12:19:082dc58ba167769f1c4c3868026cef28f311a9bffe0f07e1fa597a945cc7e0c6ccsh 
2025-04-25 12:19:076686d13aae29aa3d67bbae7b00287308d70298abd052d8086850a8dbed595a90shMirai
2025-04-25 12:19:07e8c194ab593ba81d9d0e29de0721b1947bf1373b3e347cea785491e65712ae67shMirai
2025-04-25 12:19:068237b49b2758863be8366507f4199236f489eab12bc823ee74a2db9bfa9459deshMirai
2025-04-25 12:19:06d3133fc819907723afaab93393c64bcbfe8a9125f8d77dc330b0579fd545e372elfMirai
2025-04-25 11:54:062cecf382d90634a980c0d851a89a07372ee63858ee4750d066e242d17836c023elfMirai
2025-04-25 11:54:054e5104f9e5b922366f6fab21ebaac7dcbddbae80cbc9349e5fa4c859e721302belfMirai
2025-04-25 11:54:054db20e28703aefb852e4b3e6de0db31095f19c83dc09b2556c619647bf24855eelfMirai
2025-04-25 11:54:05c8486bee71381117c6ac3d925b5bddf2f86fcb9e5d428140c4c9aa1b0001c968elfMirai
2025-04-25 11:50:05b1e106ad45b814445e8f32a7060242307c5d86f5d9b0e59017460e848860ec51elfMirai