URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 216.107.139.197
Firstseen:2026-04-07 19:35:07 UTC
Total malware sites :19
Online malware sites :17 (89%)
Offline Malware sites :2 (11%)
Newest active malware site :2026-04-08 00:00:20 UTC
Oldest active malware site :2026-04-07 19:43:11 UTC (Age: 3 days, 12 hours, 52 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-07 19:35:16 216.107.139.197Not listedAS21769 AS-COLOAM- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-08 00:00:20http://216.107.139.197/YIJFOnlineelf Ngioweb ua-wget botnetkiller
2026-04-08 00:00:20http://216.107.139.197/VCPGOnlineelf ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/QJSFOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/AWMJOnlineelf ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/EUTPOnlineelf ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/UKRPOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/YJPAOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/MGZJOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/VKZFOnlineelf ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/CSBUOnlineelf ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/HVAHOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/MPSXOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 23:59:13http://216.107.139.197/JXQJOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 23:59:10http://216.107.139.197/WZQUOnlineelf mirai ext ua-wget botnetkiller
2026-04-07 23:59:10http://216.107.139.197/JUIXOnlineelf ua-wget botnetkiller
2026-04-07 23:59:10http://216.107.139.197/XSDXOnlineelf Ngioweb ua-wget botnetkiller
2026-04-07 19:43:11http://216.107.139.197/WSW0Onlinesh ua-wget botnetkiller
2026-04-07 19:37:10http://216.107.139.197/RBW0Offlinesh ua-wget botnetkiller
2026-04-07 19:35:16http://216.107.139.197/RSW0Offlinesh ua-wget botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-08 00:00:208de4542b0cfef62851ecb166feac5ff4b0f58951e83f0e914ffe7dae90e6fed5elfNgioweb
2026-04-08 00:00:2060769cc0da4aadd603ade2a30ce4791595a43f9727e248a232ee7b6a1ae3fc44elf 
2026-04-07 23:59:135df36281969dcd0fefdc2f7bda8af95577826634311f5a82544002e7e7d4c0fdelf 
2026-04-07 23:59:13f89836639ef62ae6f317f834fab00e166ef668772b021e5e468969bd66aa4ef1elf 
2026-04-07 23:59:137524f7123eb049207efa4dac91e7d0a4726016d1a992a53468c54a4829658dbbelf 
2026-04-07 23:59:136a9a2fd72c6dd58658f09a6743885605c77be428948c72d6a4539e3982e67418elfNgioweb
2026-04-07 23:59:13d328a8df797e9a5c3c2f282b014f7cf538e141143a3054cdb542ca360d43b624elfNgioweb
2026-04-07 23:59:1325756bd4d6028d9402d02e00f7ac00bf2b23c64e420efa4be01cd965c0594b9belfNgioweb
2026-04-07 23:59:133dd83802e4a3c71b8a7a03cd7b065fbd7b9eec3ebae5e0c29d4fc09573409ed2elf 
2026-04-07 23:59:131bea422550db39a211f644ad63eeb34bce2ae9a70b39d6c38d1b423203f619d4elfNgioweb
2026-04-07 23:59:13b89e0bddab26ae722e8af161ab726eb7f25232f00b3cbdc0e6cad665513047dfelfNgioweb
2026-04-07 23:59:13acbb357150d464f678cd23159fca36575c8039f82ef9f276ef298361f8415dd5elfNgioweb
2026-04-07 23:59:13f85ee1500347ab1ae9061973abf387be54a98ad1259f5265965d5b067c170923elfNgioweb
2026-04-07 23:59:10cd6ab1ae78b810d0840c64270a6506a753befecad64eace6c1101e2a2713574felfMirai
2026-04-07 23:59:10202d1e3eccffe6ac67e54882c0e070f8a4730d5e117ed52043e4ad294ec857dbelf 
2026-04-07 23:59:10fc43bc3a09d3d47a1fa0ed5559d8d98468c07e768daf9bf1f806984b342e4aa0elfNgioweb
2026-04-07 19:43:11776b383cdfb704ff81b0db67e14d0d65db9cf107db70ce4023aac9efd5320d0ash