URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 47.96.106.127
Firstseen:2024-10-06 09:30:11 UTC
Total malware sites :2
Online malware sites :1 (50%)
Offline Malware sites :1 (50%)
Newest active malware site :2025-06-20 18:19:08 UTC
Oldest active malware site :2025-06-20 18:19:08 UTC (Age: 1 year, 2 month, 8 days, 23 hours, 3 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-10-06 09:30:12 47.96.106.127Not listedAS37963 ALIBABA-CN-NET- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-06-20 18:19:08http://47.96.106.127:8890/02.08.2022.exeOnlinecensys CobaltStrike ext DaveLikesMalwre
2024-10-11 15:58:11http://47.96.106.127:8081/02.08.2022.exeOffline abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-08-19 17:25:004cb9a808cda4eb9960816b3fa39d493ff09d9fec97138fb9004a0bce17920cc2unknown  
2025-07-14 12:04:07cf3030f89acbb73a56ff50b4f9be08f016d8ae4bc69a14160454209530a2a204unknown  
2025-06-20 18:19:0817144ab23a3b436a43134ff6a6500fc9ae3e6766adcd942abdf79fe2b6c710f7unknown  
2024-10-11 15:58:11106e6893d4e9c90b56b820b152646d75171d5221f7fc9d506550ae54bc3cc193unknown