URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 5-253-86-21.cprapid.com
Domain registrar:Tucows -
Domain registration date:2019-05-16 21:16:20 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-10-13 18:55:19 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-13 18:55:31 5.253.86.21Not listedAS213438 colocatel-inc- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-21 17:06:12http://5-253-86-21.cprapid.com/bot.i686Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 17:06:12http://5-253-86-21.cprapid.com/curl.shOfflinebotnetdomain sh BlinkzSec
2025-10-21 17:06:12http://5-253-86-21.cprapid.com/ftpget.shOfflinebotnetdomain sh BlinkzSec
2025-10-21 17:06:11http://5-253-86-21.cprapid.com/bot.mipsOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 16:50:17http://5-253-86-21.cprapid.com/bot.mipselOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 16:50:17http://5-253-86-21.cprapid.com/arm5Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 16:50:17http://5-253-86-21.cprapid.com/bot.armv7lOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 16:50:17http://5-253-86-21.cprapid.com/bot.i586Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 16:50:12http://5-253-86-21.cprapid.com/bot.armv4lOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-13 19:02:12http://5-253-86-21.cprapid.com/TOfflinebotnetdomain elf gafgyt ext BlinkzSec
2025-10-13 18:59:29http://5-253-86-21.cprapid.com/bins/XDzdfxzfOfflinebotnetdomain elf gafgyt ext BlinkzSec
2025-10-13 18:56:52http://5-253-86-21.cprapid.com/update.shOfflinebotnetdomain mirai ext sh BlinkzSec
2025-10-13 18:55:43http://5-253-86-21.cprapid.com/XDzdfxzfOfflinebotnetdomain elf gafgyt ext BlinkzSec
2025-10-13 18:55:43http://5-253-86-21.cprapid.com/a.outOfflinebotnetdomain elf gafgyt ext BlinkzSec
2025-10-13 18:55:37http://5-253-86-21.cprapid.com/lolOfflinebotnetdomain elf gafgyt ext BlinkzSec
2025-10-13 18:55:31http://5-253-86-21.cprapid.com/bins.shOfflinebotnetdomain gafgyt ext mirai ext sh BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-21 17:06:123e7604bb6c92991a3f49ae46e4e76f4a67c5711c11becad6f5e0cc2441965fectxt  
2025-10-21 17:06:128781e8ac38ff72fe2168e3b62b75db47ff3bbb90da29ce18fc4732dd261ce7f1txt  
2025-10-21 17:06:12533000a78d42bee90839ed417fb216bf9dbb6afdbb5e285efe3bda5a24d8e0a5elfMirai
2025-10-21 17:06:11b399eaf6238be55d5967d150d8ddce452ca38d9d283b5ed0a4693fecd86a8819elfMirai
2025-10-21 16:50:17c4381c1d7a61c78e12a7b903d1f5ab531c7605a814022e90f3020d0a3c3d8a15elfMirai
2025-10-21 16:50:17eaf3447663d95584650861c8c2afa0cceff6df64e0215b27ebbfa777a0c65ec7elfMirai
2025-10-21 16:50:17089c0265fe505a1bcb043536edea7517211632f208467fa52491697f36b02c0eelfMirai
2025-10-21 16:50:17e827115ddaece0476a81cd528961283e570eaa9339fb58b483c02630889064a0elfMirai
2025-10-21 16:50:1234c7bfb6808bb3b027bb6c7551cfc92e02f1748d314fe65883a01c6738c8aaeaelfMirai
2025-10-18 11:13:54fc715a7ebcb71d9020169f9bd23d12f3dfeb0aa311785cb93d5725f1b2bfe5b8shMirai
2025-10-13 19:02:12dcb9ffa705448d13eb89e12d853615e8d21c429a91a60d7bd80add94d8c4bce4elfGafgyt
2025-10-13 18:59:291b37a8704c9441ad299d064a8e910ac528deb4efe1c6fb5c4478279f31828e63elfGafgyt
2025-10-13 18:56:51725e6681c2ee8b785825687ecf79a3ced0bf2e9ccf283ca7f5b4efa0bb45ef0ashMirai
2025-10-13 18:55:43183cc6fc1130e68338d3673193df2d7f591d22143f5fd72875c37843553d5e1aelfGafgyt
2025-10-13 18:55:431b37a8704c9441ad299d064a8e910ac528deb4efe1c6fb5c4478279f31828e63elfGafgyt
2025-10-13 18:55:37210b2a799c3a67f16ce82924b0d71fee35c26402130839cf6dd3aeb3c9a859d7elfGafgyt
2025-10-13 18:55:31fc762805251333e8c824f3ed52e0171d2e24f06fe527fc43f3c2eb6dad20f15eshGafgyt