URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 42.115.68.140
Firstseen:2020-01-14 07:05:22 UTC
Total malware sites :26
Online malware sites :0 (0%)
Offline Malware sites :26 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-01-14 07:05:30 42.115.68.140Not listedAS18403 FPT-AS-AP- VNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-01 00:08:04http://42.115.68.140:58306/Mozi.mOfflineelf gafgyt ext Mozi ext lrz_urlhaus
2020-09-28 22:52:08http://42.115.68.140:58306/Mozi.aOfflineelf gafgyt ext Mozi ext lrz_urlhaus
2020-09-24 21:08:04http://42.115.68.140:48232/Mozi.mOfflineelf gafgyt ext Mozi ext lrz_urlhaus
2020-09-05 19:34:04http://42.115.68.140:57627/Mozi.mOfflineelf gafgyt ext Mozi ext lrz_urlhaus
2020-09-02 14:19:04http://42.115.68.140:35438/Mozi.aOfflineelf gafgyt ext Mozi ext lrz_urlhaus
2020-08-18 02:04:20http://42.115.68.140:35438/Mozi.mOfflineelf gafgyt ext Mozi ext lrz_urlhaus
2020-08-12 11:41:08http://42.115.68.140:43561/Mozi.aOfflineelf gafgyt ext Mozi ext lrz_urlhaus
2020-08-03 12:04:13http://42.115.68.140:43561/Mozi.mOfflinegafgyt ext Mozi ext Gandylyan1
2020-07-20 15:04:39http://42.115.68.140:56775/Mozi.mOfflinegafgyt ext Mozi ext Gandylyan1
2020-06-21 06:04:13http://42.115.68.140:57804/Mozi.mOfflinegafgyt ext Mozi ext Gandylyan1
2020-06-14 12:03:40http://42.115.68.140:47193/Mozi.mOfflinegafgyt ext Mozi ext Gandylyan1
2020-05-13 09:05:06http://42.115.68.140:57519/Mozi.mOfflinegafgyt ext Mozi ext Gandylyan1
2020-04-22 21:06:21http://42.115.68.140:42573/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-04-03 18:05:18http://42.115.68.140:41030/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-03-15 21:03:54http://42.115.68.140:58882/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-03-07 15:05:11http://42.115.68.140:40007/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-02-23 02:04:24http://42.115.68.140:57617/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-02-22 02:04:15http://42.115.68.140:36054/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-02-13 16:06:11http://42.115.68.140:57649/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-02-10 16:06:38http://42.115.68.140:38115/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-02-07 22:04:22http://42.115.68.140:45043/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-02-05 12:10:26http://42.115.68.140:53858/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-01-31 01:05:00http://42.115.68.140:47643/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-01-28 03:05:10http://42.115.68.140:59806/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-01-23 08:07:06http://42.115.68.140:33523/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1
2020-01-14 07:05:30http://42.115.68.140:49578/Mozi.mOfflineelf gafgyt ext Mozi ext Gandylyan1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-01 00:08:04c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-09-28 22:52:08c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-09-24 21:08:04c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-09-05 19:34:04c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-09-02 14:19:04c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-08-18 02:04:20c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-08-12 11:41:08c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-08-03 12:04:13c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-07-20 15:04:39c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-06-21 06:04:13c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-06-14 12:03:40c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-05-13 09:05:06c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-04-22 21:06:21c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-04-03 18:05:18c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-03-15 21:03:54c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-03-07 15:05:11c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-02-23 02:04:24c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-02-22 02:04:15c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-02-13 16:06:11c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-02-10 16:06:38c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-02-07 22:04:22c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-02-05 12:10:26c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-01-31 01:05:00c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-01-28 03:05:10c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-01-23 08:07:06c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt
2020-01-14 18:37:37285d3ca6572e18556e5e426605b357dcce06fdfec2123864c782ce63f7f578e5elf  
2020-01-14 08:15:163c4e1704c3ddd0ee2daced74abf7e344e50e8fb6ab495f400eb4a5e94acf86d2elf  
2020-01-14 07:05:28c6f6ca23761292552e6ea5f12496dc9c73374be0c5f9d0b2142ca3ae0bb8fe14elfGafgyt