URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 49.159.104.121
Firstseen:2018-11-14 21:14:01 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2018-11-14 21:14:07 49.159.104.12149-159-104-121.dynamic.elinx.com.twNot listedAS24164 UBBNET-AS-TW- TWyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2018-11-14 21:14:07http://49.159.104.121:9878/.iOfflineelf hajime zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-03-11 12:26:34766624688e95333ff3ccb3312d04d8e3e9fb3c552630ee9ccf11d86e87ca588aelf  
2019-03-09 18:54:489bcbb326a28b09faeb6fbfc0e7d68fe6ff79b7248c7b2510aa8dd11cc55e0356elf  
2019-02-26 12:16:4469b62ad1f79dbc74623d20c19600966d43acb8464f4a2d6cf4506408398b2f2belf  
2019-02-10 03:06:12fc81415c1b5d6fa48fe0e36f7864a6da96e91788d408e55b0c50ac078e8082c2elf  
2019-02-02 17:12:18b6939ce4c69d7da29576611619ae03039098bafb546e2dc55d681cd8b1b5b92celf  
2019-01-17 09:17:25c9f566e713b182b239a946968650747c85486b2131b2f036870b113cea49e61aelf  
2019-01-14 03:07:4708b24e6011c4960cac668b4fa0c54bb0ce5207a5bf7669245ec1378a963d13b0elf  
2019-01-11 11:14:21fc25983df085d7031a4028ef057a08efcd261d3e370bca6f92163a6d75f87635elf  
2019-01-11 01:59:04322566fe8c6b93ac718a60ffdc156b9b589690da7762bc5f4eec2a8ed38de2e1elf  
2019-01-02 00:10:51441719a965da87dada802ecd51d4620b76a6feb958c17cee79ecdfa1621066e8elf  
2018-12-24 07:18:24b19315d1b547b6543a5d11a0c8ec8c17195299c8dc99d57e9d0ad5bfa6ec7a22elf  
2018-12-23 23:15:2552d17a1f0b1732aedac622f917e0516e39174699ee9b2fe6dd32dad090cd5f04elf  
2018-12-20 11:29:49f4c02dcc558982d08bcfda42f637b2963f9a52b9930d364ad565d67116c44c9felf  
2018-12-20 04:52:54f0a712b4468a2ba0bee0511df056f66d3f51d66eb8460c733f73b19336370686elf  
2018-12-19 06:11:346b9815f022d9a5c247242e5bfe7199660263948228d99d0a2a1f032c95538aa1elf  
2018-12-16 01:49:40e874e713b6d03c43fc10ad947cd151b7111dbb4536a7aea2a39804d3011a72e0elf  
2018-12-15 12:36:46ee2599452b1f5e8ec41649e07cc3dd4af7470ebcfa61c5babb0cddc8a3c9403felf  
2018-12-15 04:24:03bdfbda9a9a1691ff14c51c323872f0dbe304448b6b45e91f491e5f15326bab5delf  
2018-12-15 03:19:42e86ddd14a376ccf252ec48ee9132afa26aadb6fdb3089b65e87dc760af26c345elf  
2018-12-14 00:35:0145b55afb003c5a6195b3ff30480954b42a8f19813751e1a6089b72f91f036ebdelf  
2018-12-13 06:30:200518e274a0e624677e3152d887f1d337cfeb993a0d0f7d92273c07eee686fafdelf  
2018-12-12 15:30:33beb05ce47c2db073f429446e56200ddec4bef0928f1b73d6ba98e0a420b9d96felf  
2018-12-11 12:25:58d6d5a7a89431c7f99aae6ae0a9d88c3ab71528de8fd4020fe683e3e22b86f37felf  
2018-12-11 09:22:32afb54a343ebc42ddaf7b4e3999f81a1801b4cac53aaff5395e9b4de941c42463elf  
2018-12-09 23:49:54ca5f7b054e58918e4a095f6042d972040ba567bf28f1ae785ce52d24b868deeaelf  
2018-12-09 06:00:455b3f9c9e26876697556bcc050da24c6324df923f8b996e3148576464a77ea7ddelf  
2018-12-09 04:28:04e04aa29e52989335b9bb5b46b43604d6022e22a9a1fe3c357488e48aaf51c25belf  
2018-12-08 08:31:4517e070e9b5acfa337b368c2d3284f0cb9a1cc5f42f1f42b621b666f198bfe39belf  
2018-12-07 04:40:58c84d5f0c89004d96221e5ddd371af60d0e4c9f56a47b2123ec6baa874b89f482elf  
2018-12-06 02:08:44ebafa0ed47cd856a9cd9a27eb4e8827ed15edc3d4457320e2ca4aa51e371a919elf  
2018-12-04 10:43:457c59b2374f7956a1628893270fa1f9f128466875cacf4cd843dbe7b6c4b9722aelf  
2018-11-14 21:14:05a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3elfHajime