URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 31.56.209.8
Firstseen:2026-05-19 23:33:05 UTC
Total malware sites :14
Online malware sites :4 (29%)
Offline Malware sites :10 (71%)
Newest active malware site :2026-05-20 00:06:16 UTC
Oldest active malware site :2026-05-20 00:04:21 UTC (Age: 6 days, 13 hours, 19 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-05-19 23:33:15 31.56.209.8SBL695375AS209373 SWISSNET-AS- AEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-05-20 21:23:17http://31.56.209.8/o.xmlOfflinesh ua-wget xml botnetkiller
2026-05-20 00:06:16http://31.56.209.8/wife.spcOnlineelf ua-wget botnetkiller
2026-05-20 00:05:25http://31.56.209.8/wife.arm5Onlineelf mirai ext ua-wget botnetkiller
2026-05-20 00:05:22http://31.56.209.8/wife.arm6Offlineelf mirai ext ua-wget botnetkiller
2026-05-20 00:05:15http://31.56.209.8/wife.ppcOfflineelf gafgyt ext ua-wget botnetkiller
2026-05-20 00:05:15http://31.56.209.8/wife.i686Offlineelf gafgyt ext ua-wget botnetkiller
2026-05-20 00:05:15http://31.56.209.8/wife.mpslOfflineelf gafgyt ext ua-wget botnetkiller
2026-05-20 00:05:15http://31.56.209.8/wife.arm4Offlineelf gafgyt ext ua-wget botnetkiller
2026-05-20 00:04:21http://31.56.209.8/wife.mipsOnlineelf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-20 00:04:21http://31.56.209.8/wife.arm7Offlineelf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-20 00:04:21http://31.56.209.8/wife.i486Offlineelf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-20 00:04:21http://31.56.209.8/wife.m68kOnlineelf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-20 00:04:21http://31.56.209.8/wife.sh4Offlineelf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-19 23:33:15http://31.56.209.8/wife.x86Offlineelf gafgyt ext mirai ext ua-wget x86 botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-26 13:22:27cad50090e0b22beb375242a4d32befb4b0ca721860a927b4187e7c6eb1341f27elf  
2026-05-26 13:06:27409a387d0eb9b361a90f0b6da9ec4d1c64299bf738a42f24f4dbd52e5f5bdf5celfMirai
2026-05-26 13:05:55043fbcda469ba6cb56b7cef10fde7fa49346430433c97ffcde024b0739eb08ebelfMirai
2026-05-26 12:56:3051973735afcf0f750d1dacc6402d4cf1282a7d84f28b73e71f5c617e68166662elfMirai
2026-05-22 12:46:25a6a80aebc206c51e3143c0a4663edf8ed261844500325b6b954dd1af30c56524elfGafgyt
2026-05-20 21:23:17b2910520cdc56927fef6674d14d1f8ca09135c56336ef18c74a2fed745614ff1sh 
2026-05-20 14:02:16f6bedc536070b9566caa48266a5e89db15dde879c277fce7c16e54f26916898eelfGafgyt
2026-05-20 14:00:133973c4c532316ab4277387ed0ee9655ee2944fd7c3c1e2a4714571652aa06793elfGafgyt
2026-05-20 13:44:21f5c6a753f0c762b807be5a5960d8dde8eadbbaa7bd9ace17dfdafce96de0adbbelfGafgyt
2026-05-20 13:36:48701c10939f8a6ea704ed087cb65c5db596a9738d9a239a2eb54612bdaedd034felfGafgyt
2026-05-20 13:16:02c1e5408dbbbde092f14cefe945d3e9ee964525bc9078a4c67baabae134af3cadelfMirai
2026-05-20 13:05:48ffa171ae48bf6f3f2f776348abfbf667e7104f836384a85d65273ce17a323f74elfGafgyt
2026-05-20 13:02:51da1fd6b095a66395aee34c7c602b57d1f59d93246ef1f425ff0ce825d98a9625elfMirai
2026-05-20 12:58:4969320c8a40d3988e63990f18dc26d400f301bf62f8d22459411a5d4f9a57721eelfGafgyt
2026-05-20 12:55:36fad549f8dc80a78439d0c40bef6d961606cea4a9796440d9b464f5f4d8c31f65elfMirai
2026-05-20 12:53:54a6c29cd6e74551546477f059f6f1ac971f296c0f4f82d81e7280487d1de925ecelfGafgyt
2026-05-20 12:48:27f5f10c1ce7447aa69ac6dd0a5037ed61e29fa9bd2712ad07d351f444393cdf66elfGafgyt
2026-05-20 12:47:30feb99308d96e880d3629296961454f0e496eecb45ba55d3eb24cd961db4b5d04elf 
2026-05-20 12:34:052d318335eb73d019766af06ec6eb4a2fc6738cb64ea97485d5f0b9198161305felfGafgyt
2026-05-20 00:06:16f13e7023cb284e9dee8e1210ea94ee3ae18eb30a5de898e380462d43a47e9b98elf 
2026-05-20 00:05:2510e898e98124f96977df73946a7fdfbdf188b53b3c0ae7e175f65a8a65c9e62celfMirai
2026-05-20 00:05:221f05f807afc9a7ca8ab11b8868207ae008cbafcd9616723e538f8678e535dca2elfMirai
2026-05-20 00:05:15a3b6a14830d4f3e13e1f6fd186de1abba66032d57968eb01160af6255a429155elfGafgyt
2026-05-20 00:05:1550b7f0cd51d96ec93163b72445d8c78f6298aae574e762245e0b4a7163981f98elfGafgyt
2026-05-20 00:05:158fa147b56df34da1cd6295a45d6ed8d9bdd02b44bd4967cc144c4feb789504f1elfGafgyt
2026-05-20 00:05:15335a0bf1ced7d264936850e34dd9702b756019536b59a77371b715d3ba4e573belfGafgyt
2026-05-20 00:04:2189563f414516be6c20e1e2121c5639b794f8981c7bc7bd2f683d7732e698466aelfMirai
2026-05-20 00:04:2178fcc0fb163fcec15e9fd30331f42ffc267bf265f1ef25d80b6bbc181f10897celfMirai
2026-05-20 00:04:21b644b7af2631a559e95ddba16c5cf91e442854ebb4b2b432cd5a227b9d18a153elfMirai
2026-05-20 00:04:217b49489844af3f7e9010b3bd6eead9852ce11abb673cb6354bb79775d4cb9593elfMirai
2026-05-20 00:04:214b53ef040222435d974b2595e6bc3e0c1196f8d2f9a19417e64e1ed7caf0d67eelfMirai
2026-05-19 23:33:14c859725375e28257c471a3f46b2cf1083d7bdb3d3a3020f9dfa9fd6e8fc4dd40elfMirai