URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 221.158.86.16
Firstseen:2024-06-08 08:00:09 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-06-08 08:00:25 221.158.86.16Not listedAS4766 KIXS-AS-KR- KRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-06-26 08:00:21http://221.158.86.16:1189/svchcst.exeOfflineGh0stRAT misa11n
2024-06-23 08:00:17http://221.158.86.16:7762/svchost.exeOfflineGh0stRAT misa11n
2024-06-18 08:00:17http://221.158.86.16:2266/AV520.exeOfflineGh0stRAT misa11n
2024-06-13 08:00:28http://221.158.86.16:7744/svchvst.exeOfflineGh0stRAT misa11n
2024-06-08 08:00:25http://221.158.86.16:4466/svchost.exeOfflineGh0stRAT misa11n