URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 34.70.205.211
Firstseen:2026-01-24 20:47:04 UTC
Total malware sites :6
Online malware sites :4 (67%)
Offline Malware sites :2 (33%)
Newest active malware site :2026-01-24 21:05:19 UTC
Oldest active malware site :2026-01-24 21:04:06 UTC (Age: 1 day, 2 hours, 25 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-24 20:47:20 34.70.205.211211.205.70.34.bc.googleusercontent.comNot listedAS396982 GOOGLE-CLOUD-PLATFORM- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-25 08:51:05http://34.70.205.211/plugins-dist/safehtml/lang...Offlinescript sh ua-wget mhagen
2026-01-24 21:05:19http://34.70.205.211/plugins-dist/safehtml/lang...Onlinesh ua-wget NDA0E
2026-01-24 21:04:19http://34.70.205.211/plugins-dist/safehtml/lang...OnlineCoinMiner elf ua-wget NDA0E
2026-01-24 21:04:06http://34.70.205.211/plugins-dist/safehtml/lang...Onlinegz tar tgz ua-wget NDA0E
2026-01-24 21:04:06http://34.70.205.211/plugins-dist/safehtml/lang...Onlinegz tar tgz ua-wget NDA0E
2026-01-24 20:47:20http://34.70.205.211/plugins-dist/safehtml/lang...Offlinesh ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-24 21:05:1972ec88c4f57ff222abe8a49809e149cb68daa1bbf77147b946f3e0cbfcf411aesh 
2026-01-24 21:04:191ff55eafdba615287f423eab3257ad24b070be1a6e63aa91f06d0ba16d001b60elfCoinMiner
2026-01-24 21:04:06d7c569900cd7cdcaafdc0de74de12cc44988f7ad76917b5a2c224aa9de5fc3f8unknown  
2026-01-24 21:04:0616ac8c14e7c5d9b0e573f42125b2c41fa0627243a84fcf37fc1d166ab824b64eunknown