URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 213.232.114.14
Firstseen:2026-08-26 05:37:05 UTC
Total malware sites :10
Online malware sites :10 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-08-26 10:01:52 UTC
Oldest active malware site :2026-08-26 05:37:17 UTC (Age: 19 hours, 34 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-08-26 05:37:17 213.232.114.14Not listedAS3214 XTOM- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-08-26 10:01:52http://213.232.114.14/SH4Onlinegafgyt ext cesnet_certs
2026-08-26 10:01:45http://213.232.114.14/I686Onlinemirai ext cesnet_certs
2026-08-26 10:01:35http://213.232.114.14/M68KOnlinemirai ext cesnet_certs
2026-08-26 10:01:34http://213.232.114.14/ARMV6LOnlinemirai ext cesnet_certs
2026-08-26 10:01:25http://213.232.114.14/I586Onlinemirai ext cesnet_certs
2026-08-26 10:01:16http://213.232.114.14/MIPSOnlinemirai ext cesnet_certs
2026-08-26 10:01:16http://213.232.114.14/MIPSELOnlinemirai ext cesnet_certs
2026-08-26 05:37:20http://213.232.114.14/X86_64Onlinebotnet ddos elf iot KHserver mirai ext eFeSpain
2026-08-26 05:37:19http://213.232.114.14/ARMV4LOnlinebotnet ddos elf iot KHserver mirai ext eFeSpain
2026-08-26 05:37:17http://213.232.114.14/handshakebins.shOnlineascii mirai ext geenensp