URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
| Host: | 31.76.20.19 |
|---|---|
| Firstseen: | 2026-08-14 05:15:05 UTC |
| Total malware sites : | 8 |
| Online malware sites : | 8 (100%) |
| Offline Malware sites : | 0 (0%) |
| Newest active malware site : | 2026-08-14 05:15:25 UTC |
| Oldest active malware site : | 2026-08-14 05:15:24 UTC (Age: 3 days, 5 hours, 41 minutes) |
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2026-08-14 05:15:24 | 31.76.20.19 | Not listed | AS215439 PLAY2GO-NET | DE | yes |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2026-08-14 05:15:25 | http://31.76.20.19/armv6l | Online | 31-76-20-19 elf ua-wget | |
| 2026-08-14 05:15:25 | http://31.76.20.19/mips | Online | 31-76-20-19 DDoSAgent elf ua-wget | |
| 2026-08-14 05:15:24 | http://31.76.20.19/armv7l | Online | 31-76-20-19 elf mirai | |
| 2026-08-14 05:15:24 | http://31.76.20.19/i686 | Online | 31-76-20-19 DDoSAgent elf ua-wget | |
| 2026-08-14 05:15:24 | http://31.76.20.19/x86 | Online | 31-76-20-19 DDoSAgent elf ua-wget | |
| 2026-08-14 05:15:24 | http://31.76.20.19/mipsel | Online | 31-76-20-19 DDoSAgent elf ua-wget | |
| 2026-08-14 05:15:24 | http://31.76.20.19/ppc64 | Online | 31-76-20-19 DDoSAgent elf ua-wget | |
| 2026-08-14 05:15:24 | http://31.76.20.19/armv5l | Online | 31-76-20-19 elf ua-wget |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2026-08-14 05:15:24 | bb63f72772468d22fde5732730a2606d0f1d69b7051a0e97c12c350432d3885d | elf | Mirai | |
| 2026-08-14 05:15:24 | 4cacf3825ead32adbdab35a419255d815f0115bf3cc6395d543dcc72beda8f94 | elf | DDoSAgent | |
| 2026-08-14 05:15:24 | 4cacf3825ead32adbdab35a419255d815f0115bf3cc6395d543dcc72beda8f94 | elf | DDoSAgent | |
| 2026-08-14 05:15:24 | 1bad704a3320fe86f93a7afb94a310334abac519c81bc000514541696afff9f7 | elf | DDoSAgent | |
| 2026-08-14 05:15:24 | 25a91988a970a268cb6e0d6ffcf116b33f9aa12d0ec847bfa75e30fab9b109e5 | elf | DDoSAgent | |
| 2026-08-14 05:15:24 | e1fe2086329da141df89da4056c556eb5ccb1d7aeff9ca1475477bef0d389408 | elf | ||
| 2026-08-14 05:15:24 | 7b1985fd9824ec0813a2fa8a47cf7a9ef29f8001407aace06952a118011a29b0 | elf | ||
| 2026-08-14 05:15:24 | 435451564bf7dc7c99d7f86cd667ea4b1122e0316843cdb581da65ea66d9d61e | elf | DDoSAgent |
DE