URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 23.94.148.10
Firstseen:2023-02-21 14:34:03 UTC
Total malware sites :23
Online malware sites :0 (0%)
Offline Malware sites :23 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-02-21 14:34:10 23.94.148.1023-94-148-10-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-04-10 06:51:06http://23.94.148.10/8UsA.shOfflineelf shellscript abus3reports
2024-04-09 16:00:12http://23.94.148.10/AB4g5/Josho.spcOfflineelf mirai ext BlinkzSec
2024-04-09 16:00:08http://23.94.148.10/AB4g5/Josho.armOfflineelf mirai ext BlinkzSec
2024-04-09 14:59:13http://23.94.148.10/AB4g5/Josho.mipsOfflineelf mirai ext ClearlyNotB
2024-04-09 14:59:12http://23.94.148.10/AB4g5/Josho.x86Offlineelf mirai ext ClearlyNotB
2024-04-09 14:59:11http://23.94.148.10/AB4g5/Josho.arm6Offlineelf mirai ext ClearlyNotB
2024-04-09 14:59:11http://23.94.148.10/AB4g5/Josho.arm7Offlineelf mirai ext ClearlyNotB
2024-04-09 14:59:08http://23.94.148.10/AB4g5/Josho.ppcOfflineelf mirai ext ClearlyNotB
2024-04-09 14:59:08http://23.94.148.10/AB4g5/Josho.sh4Offlineelf mirai ext ClearlyNotB
2024-04-09 14:59:08http://23.94.148.10/AB4g5/Josho.m68kOfflineelf mirai ext ClearlyNotB
2024-04-09 14:59:08http://23.94.148.10/AB4g5/Josho.arm5Offlineelf mirai ext ClearlyNotB
2024-04-09 14:59:08http://23.94.148.10/AB4g5/Josho.mpslOfflineelf mirai ext ClearlyNotB
2024-02-21 07:23:09http://23.94.148.10/8080/ORR.txtOfflineAgentTesla ext ascii Encoded abuse_ch
2024-02-21 07:22:07http://23.94.148.10/gh/dasleodasgoodtohearthath...OfflineAgentTesla ext doc abuse_ch
2024-02-21 07:22:07http://23.94.148.10/8080/oceanfishgood.vbsOfflineAgentTesla ext vbs abuse_ch
2023-02-27 16:26:03http://23.94.148.10/1200/vbc.exeOfflineAgentTesla ext dofoil ext exe opendir Smoke Loader ext abuse_ch
2023-02-27 07:51:04http://23.94.148.10/1500/vbc.exeOfflinedofoil ext exe opendir Smoke Loader ext abuse_ch
2023-02-25 02:24:04http://23.94.148.10/6333/vbc.exeOffline32 exe PureCrypter zbetcheckin
2023-02-24 13:50:07http://23.94.148.10/9019/vbc.exeOfflineAgentTesla ext exe opendir PureCrypter abuse_ch
2023-02-23 12:00:08http://23.94.148.10/6222/vbc.exeOfflineAgentTesla ext exe opendir abuse_ch
2023-02-23 01:29:04http://23.94.148.10/9091/vbc.exeOffline32 AgentTesla ext exe zbetcheckin
2023-02-22 03:43:04http://23.94.148.10/5352/vbc.exeOffline32 AgentTesla ext exe zbetcheckin
2023-02-21 14:34:10http://23.94.148.10/5353/vbc.exeOfflinedofoil ext exe Smoke Loader ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-04-10 06:51:06ff583dd20f9bf86a7bb59d498eb0ec18040a8d46f487c23e95c78c9d4d7c2e6esh  
2024-04-09 16:00:12325102ce52388e9f959d389072c8a18405ac5ba242fc43d0adc6411d0ddfe4acelfMirai
2024-04-09 16:00:08216d96fc1155ee83bb36e979ca6f7369740dfb323fab1f509aa70121deb9c9b2elfMirai
2024-04-09 14:59:13de88e29d0b14eb903d947330ac0777eb7155724a2bd166775733b48531d2662belfMirai
2024-04-09 14:59:1280b084205d889b095afb8cd039f17d286e7a9b5bb4e80b277777bd4d7f19d788elfMirai
2024-04-09 14:59:119d18ce9d7b7c58d2175c67107baf866cb86369cf8acd195959fd776957c0d1acelfMirai
2024-04-09 14:59:11d4d5ff38d0192de8e3bb5d7299b72f7224c5b010a7ec5beb591f24654a3704d1elfMirai
2024-04-09 14:59:088c1372b43f4fd33079afb19a610e3d885bea87d8b52b3df8d937ff3022266e31elfMirai
2024-04-09 14:59:087949110bf277ffffbf7ee9bf6fdfba96e67d92220342169d2fd429fc5382d79felfMirai
2024-04-09 14:59:08cec8fa5aa532c966d4d1569268e50bc9d3f96e0e60f2c52325345542285606beelfMirai
2024-04-09 14:59:0838a47c550fc9f39b5db66e8d1870e58b894fb3145c70d8779b421d7f60e03740elfMirai
2024-04-09 14:59:08ac76bd907867f086264cc318e70ae3b450ffe8dc161043bf048b7cf733e133ceelfMirai
2024-02-21 07:23:092e11cb655e4904ae7a4a71bbc9dd816387233fb351bcdcc0c293a2e177389139txt AgentTesla
2024-02-21 07:22:07464c336ea903590b0ccc26e8eaa734e8b819b31f860d0d20a67d3239b2cc7f92unknown  
2024-02-21 07:22:07cdcc57561272761db4bcb04e3b40e6a8909d2eef8e912a5e92359275f370827aunknown  
2023-02-27 16:26:038aee9133ba74e4c5b6d88322225550e2137f32da78a987ce30a024bcd1a3d581exeAgentTesla
2023-02-27 09:13:50387cb0c7adfffe604b16d02cad4c9fba30e4a497dd0f442fb41c00e45bc6274aexeSmoke Loader
2023-02-27 07:51:049b639a03cd559f3cb93d95c55a5680a66cadd2b085764f90313c7f971d0daf8fexe 
2023-02-25 02:24:036117bcb631fe98190f2a23cb1854690eba95e9b33d1cdaba222e9f8b17665319exePureCrypter
2023-02-24 13:50:07c5f8a57e9e252306e9876a01fbc423420693bf04cf7c33fb0bbf972e34299f21exeAgentTesla
2023-02-23 12:00:08e18cf6502122b168dac6c932cd89739e313154ee9b73d6ddd692d4ad990aceb0exeAgentTesla
2023-02-23 01:29:04310d2c681b2bdfa3dacbfbbc88504e71b260f442071c624558d747e6fe2a1c3bexeAgentTesla
2023-02-22 03:43:04310d2c681b2bdfa3dacbfbbc88504e71b260f442071c624558d747e6fe2a1c3bexeAgentTesla
2023-02-22 01:58:22a46434b854d81beb15a4e601ce885712d6d0081b8b68f0e4ffc6a1f1a1b517cdexeSmoke Loader
2023-02-21 14:34:0431d27525497d7f30c165e944ff59fd2e4a928c11f00abe3157bce9dabc665e11exeSmoke Loader