URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 213.101.148.245
Firstseen:2020-05-12 05:26:04 UTC
Total malware sites :20
Online malware sites :0 (0%)
Offline Malware sites :20 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-12 05:26:06 213.101.148.245static-213-101-148-245.cust.tele2.ltNot listedAS1257 SWIPNET- LTyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-15 23:53:34http://213.101.148.245:43073/mozi.aOffline tammeto
2022-09-26 12:04:34http://213.101.148.245:43073/Mozi.mOfflineMozi ext Gandylyan1
2022-07-01 18:03:33http://213.101.148.245:49237/Mozi.mOfflineMozi ext Gandylyan1
2022-03-14 14:54:33http://213.101.148.245:33947/mozi.mOffline tammeto
2021-12-31 15:26:33http://213.101.148.245:58372/mozi.mOffline tammeto
2021-12-29 16:41:31http://213.101.148.245:58372/Mozi.aOfflineMozi ext Petras_Simeon
2021-12-04 19:10:33http://213.101.148.245:60244/mozi.aOffline tammeto
2021-11-21 18:50:33http://213.101.148.245:56612/mozi.mOffline tammeto
2021-11-14 00:09:33http://213.101.148.245:56612/mozi.aOffline tammeto
2021-11-03 06:03:33http://213.101.148.245:52884/mozi.mOffline tammeto
2021-10-31 12:51:32http://213.101.148.245:52884/mozi.aOffline tammeto
2021-10-04 21:03:33http://213.101.148.245:42516/Mozi.mOfflineMozi ext Gandylyan1
2021-09-11 09:07:33http://213.101.148.245:42516/mozi.aOffline tammeto
2021-08-18 07:21:33http://213.101.148.245:38234/mozi.aOffline tammeto
2021-08-11 15:57:32http://213.101.148.245:38234/mozi.mOffline tammeto
2021-01-28 10:53:03http://213.101.148.245:48354/iOffline32-bit arm elf mirai ext geenensp
2021-01-28 10:26:04http://213.101.148.245:48354/bin.shOffline32-bit arm elf mirai ext geenensp
2020-12-25 23:03:04http://213.101.148.245:57013/bin.shOffline32-bit arm elf mirai ext geenensp
2020-12-25 22:26:04http://213.101.148.245:57013/iOffline32-bit arm elf mirai ext geenensp
2020-05-12 05:26:06http://213.101.148.245:54838/.iOffline32-bit arm elf hajime geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-01-28 10:53:0312013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2021-01-28 10:26:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-25 23:03:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-25 22:26:0412013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0efelfMirai
2020-12-15 23:23:21de35dd093b49a69ed296c985fb79ca02cb569ab6363d7b852835196adb93c467elf  
2020-12-10 23:26:453fb0adfcb069856e09fe25ea276c02f4de85a56de6199d7cbd302414e87774ecelf  
2020-12-06 22:04:36956567d666b24e0ca5ebe26a1ae509904a18726c65d6272122afef35b18d8a9celf  
2020-12-06 01:29:466368881a69d1b4584726e64d7d44b1a59cc825d244ddfc99b4042ff694c4eecfelf  
2020-12-04 02:45:3811cfb588570cd6fce460101e5edd4d59577b700a633d6d9cd35ac7c5892fca51elf  
2020-12-01 13:17:30db89f242edf8316a79d83959989382b08b9848095a874074717aa22822ba4821elf  
2020-12-01 12:38:564a166cdb8854c55439677b464d382c35ae1be7fd889f684438f66ac37067ae3belf  
2020-11-20 09:31:377cafda67b769e284565d1e7192fa04263dcbcc7121806d36ac1eefd1b20c2561elf  
2020-11-18 11:25:00c65cf14d434fc10561a3c305928d0eae84f9371849b6a1ca3e9a727b5096ef44elf  
2020-11-17 10:53:18445ed7a8723afb61e3f2d8e6127c16fa22b6d5ff23a2d2b0ba0054c72499f897elf  
2020-10-23 21:22:190206196336adaa68295a278fe21307f46a9f8e03556d92e77b808dc04f537ac1elf  
2020-10-01 02:39:262fdd61169835c86ec368e7274beaa8363f173a5623bcc8b62e6bb4a41407ec2celf  
2020-09-15 17:18:08eccf0707348217cd77a24b19b9d015e76ef5e130d8b07f765467bd78e3dea30felf  
2020-09-14 14:43:1862c95076a818e7d23cfc3623d9d23c2e8bec9575fb8663f8a2f4592ab287e382elf  
2020-08-09 14:03:5315ecf36de8924c82f224953100fbebe7397b1d7739f0f1271cc28479be1c522belf  
2020-07-04 18:28:282cd2d296a61cb6d28e5405f90034a6cfb2f25d34dd351277a06b1860a1de257eelf  
2020-06-15 20:27:3841c7b49ce72c6c1964d33059f74e42e1d44c8b5646730fa1811c2e09f8bc55e4elf  
2020-06-11 20:08:35fedceb64e7c9f737b061fe13be840d31a996c1ba4921728701b59ed369bef06felf  
2020-05-12 05:26:05a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3elfHajime