URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 23.132.228.234
Firstseen:2025-12-02 06:23:06 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-02 06:23:13 23.132.228.234Not listedAS6517 LAKENETWORKS-AS- ITyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-02 06:23:22http://23.132.228.234/mori.vtuberOfflinemirai ext juroots
2025-12-02 06:23:22http://23.132.228.234/kiara.vtuberOfflinemirai ext juroots
2025-12-02 06:23:22http://23.132.228.234/laplus.vtuberOfflinemirai ext juroots
2025-12-02 06:23:22http://23.132.228.234/shion.vtuberOfflinemirai ext juroots
2025-12-02 06:23:21http://23.132.228.234/vtubers.shOfflineCoinMiner juroots
2025-12-02 06:23:21http://23.132.228.234/towa.vtuberOffline juroots
2025-12-02 06:23:21http://23.132.228.234/pekora.vtuberOffline juroots
2025-12-02 06:23:21http://23.132.228.234/haachama.vtuberOffline juroots
2025-12-02 06:23:21http://23.132.228.234/subaru.vtuberOffline juroots
2025-12-02 06:23:21http://23.132.228.234/marine.vtuberOffline juroots
2025-12-02 06:23:21http://23.132.228.234/fubuki.vtuberOffline juroots
2025-12-02 06:23:21http://23.132.228.234/ayame.vtuberOffline juroots
2025-12-02 06:23:19http://23.132.228.234/mumei.vtuberOffline juroots
2025-12-02 06:23:19http://23.132.228.234/amelia.vtuberOffline juroots
2025-12-02 06:23:18http://23.132.228.234/gura.vtuberOffline juroots
2025-12-02 06:23:13http://23.132.228.234/korone.vtuberOfflineDDoSAgent juroots

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-12-02 06:23:229b500ff92452936ce8b7c4037332748aeaf5ff8af167ec7b0d9bde9f93983c66elfMirai
2025-12-02 06:23:2269370ab87dc801f86a654916c0401edf2eab0dea21d7951ca24d645aafdaf7deelfMirai
2025-12-02 06:23:22fc491aec4061f8dd019b6e30068fc1f69844cbd16f4bf3cab677d54cd84c8ed3elfMirai
2025-12-02 06:23:222a66f597ee9bf3c1dcac047ba02afbb90e0adce6e7e553cc0901c78f37c6c7a2elfMirai
2025-12-02 06:23:21c12fbf5b9b42b810a1eb9649e4f9b71dd320967fd8f34ca86ca8bae447deef32elf 
2025-12-02 06:23:2122605f5d5907d3cb1013ebabe9ef54fedf2b394f5f4b495d31f0511f44fd0058elf 
2025-12-02 06:23:21ca8b45135139eb0b66f85a95a03a30a71410c2f5013a45d1e8409e37ded9a909elf 
2025-12-02 06:23:21d472c7ef1fc069fd1a8c83f04552f994153d6f74eedd138cd991c016ab46b22eelf 
2025-12-02 06:23:21c4259ce5d7a71e6d4a3f17f3675250f840e4b9c1b9ec89ad8319bf3916d281c1elf 
2025-12-02 06:23:21b19a349cac773606d28a94b5ef5f2708f1799eabca281a5a29e9f32c9a32b929elf 
2025-12-02 06:23:204720ee78506641aeaf6f5dc471d121014c9db72007acff2712ee1a9d31dade3atxtCoinMiner
2025-12-02 06:23:20c12fbf5b9b42b810a1eb9649e4f9b71dd320967fd8f34ca86ca8bae447deef32elf 
2025-12-02 06:23:1999e20add7d779da22b809938e0cbf50f7ddeb1cb308c8480efe0e0dc310d594belf 
2025-12-02 06:23:18d7a9a49f61d323d69768737f47983e0820635d61bc96b1b9eda0ae9a92649f8celf 
2025-12-02 06:23:185dddfd8af478caa5c53c98306ab9461980d355ef38a4158ce9157ddcda3dc30celf 
2025-12-02 06:23:1246786d58742fd93be9cba4f1b6bb25468f6c4a6ef888355dc780ef730019d7c2elfDDoSAgent