URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 5.253.86.21
Firstseen:2025-10-10 21:32:04 UTC
Total malware sites :39
Online malware sites :0 (0%)
Offline Malware sites :39 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-10 21:32:06 5.253.86.21Not listedAS213438 colocatel-inc- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-21 16:43:07http://5.253.86.21/arm5Offlineelf mirai ext BlinkzSec
2025-10-21 16:43:05http://5.253.86.21/ftpget.shOfflinesh BlinkzSec
2025-10-21 16:43:05http://5.253.86.21/curl.shOfflinesh BlinkzSec
2025-10-18 15:45:26http://5.253.86.21/bot.i686Offlineelf mirai ext ua-wget abuse_ch
2025-10-18 15:45:26http://5.253.86.21/bot.i586Offlineelf mirai ext ua-wget abuse_ch
2025-10-18 15:45:26http://5.253.86.21/bot.armv7lOfflineelf mirai ext ua-wget abuse_ch
2025-10-18 15:45:26http://5.253.86.21/bot.mipsOfflineelf mirai ext ua-wget abuse_ch
2025-10-18 15:45:26http://5.253.86.21/bot.mipselOfflineelf mirai ext ua-wget abuse_ch
2025-10-18 15:45:26http://5.253.86.21/bot.armv4lOfflineelf mirai ext ua-wget abuse_ch
2025-10-18 15:45:25http://5.253.86.21/bot.armv5lOfflineelf ua-wget abuse_ch
2025-10-13 18:56:44http://5.253.86.21/TOfflineelf gafgyt ext BlinkzSec
2025-10-13 18:54:49http://5.253.86.21/lolOfflineelf gafgyt ext BlinkzSec
2025-10-11 06:47:20http://5.253.86.21/DFhxdhdfOfflineelf ua-wget abuse_ch
2025-10-11 06:47:19http://5.253.86.21/bins/keksec.x86Offlineelf ua-wget abuse_ch
2025-10-11 06:47:19http://5.253.86.21/bins/keksec.arm5Offlineelf ua-wget abuse_ch
2025-10-11 06:47:19http://5.253.86.21/bins/keksec.i586Offlineelf ua-wget abuse_ch
2025-10-11 06:47:17http://5.253.86.21/bins/keksec.spcOfflineelf ua-wget abuse_ch
2025-10-11 06:47:16http://5.253.86.21/bins/keksec.mipsOfflineelf ua-wget abuse_ch
2025-10-11 06:47:16http://5.253.86.21/bins/keksec.ppc-440fpOfflineelf ua-wget abuse_ch
2025-10-11 06:47:16http://5.253.86.21/bins/keksec.arm7Offlineelf ua-wget abuse_ch
2025-10-11 06:47:16http://5.253.86.21/JIPJIPJjOfflineelf ua-wget abuse_ch
2025-10-11 06:47:12http://5.253.86.21/jhUOHOfflineelf ua-wget abuse_ch
2025-10-11 06:47:12http://5.253.86.21/GHfjfgvjOfflineelf ua-wget abuse_ch
2025-10-11 06:47:12http://5.253.86.21/UYyuyioyOfflineelf ua-wget abuse_ch
2025-10-11 06:47:12http://5.253.86.21/bins/keksec.mpslOfflineelf ua-wget abuse_ch
2025-10-11 06:47:12http://5.253.86.21/bins/keksec.armOfflineelf ua-wget abuse_ch
2025-10-11 06:47:11http://5.253.86.21/bins/keksec.ppcOfflineelf ua-wget abuse_ch
2025-10-11 06:47:11http://5.253.86.21/FTUdftuiOfflineelf ua-wget abuse_ch
2025-10-11 06:47:11http://5.253.86.21/FDFDHFCOfflineelf ua-wget abuse_ch
2025-10-11 06:47:11http://5.253.86.21/JIPJuipjhOfflineelf ua-wget abuse_ch
2025-10-11 06:47:11http://5.253.86.21/bins/keksec.sh4Offlineelf ua-wget abuse_ch
2025-10-11 06:47:11http://5.253.86.21/RYrydryOfflineelf ua-wget abuse_ch
2025-10-11 06:47:06http://5.253.86.21/bins/keksec.x64Offlineelf ua-wget abuse_ch
2025-10-11 06:47:06http://5.253.86.21/bins/keksec.m68kOfflineelf ua-wget abuse_ch
2025-10-10 21:32:20http://5.253.86.21/update.shOfflinemirai ext opendir DaveLikesMalwre
2025-10-10 21:32:19http://5.253.86.21/bins/XDzdfxzfOfflinegafgyt ext opendir DaveLikesMalwre
2025-10-10 21:32:06http://5.253.86.21/a.outOfflinegafgyt ext opendir DaveLikesMalwre
2025-10-10 21:32:06http://5.253.86.21/XDzdfxzfOfflinegafgyt ext opendir DaveLikesMalwre
2025-10-10 21:32:06http://5.253.86.21/bins.shOfflinegafgyt ext mirai ext opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-21 22:35:068781e8ac38ff72fe2168e3b62b75db47ff3bbb90da29ce18fc4732dd261ce7f1txt  
2025-10-21 21:57:113e7604bb6c92991a3f49ae46e4e76f4a67c5711c11becad6f5e0cc2441965fectxt  
2025-10-21 16:43:06089c0265fe505a1bcb043536edea7517211632f208467fa52491697f36b02c0eelfMirai
2025-10-18 15:45:2634c7bfb6808bb3b027bb6c7551cfc92e02f1748d314fe65883a01c6738c8aaeaelfMirai
2025-10-18 15:45:26533000a78d42bee90839ed417fb216bf9dbb6afdbb5e285efe3bda5a24d8e0a5elfMirai
2025-10-18 15:45:26c4381c1d7a61c78e12a7b903d1f5ab531c7605a814022e90f3020d0a3c3d8a15elfMirai
2025-10-18 15:45:26eaf3447663d95584650861c8c2afa0cceff6df64e0215b27ebbfa777a0c65ec7elfMirai
2025-10-18 15:45:26b399eaf6238be55d5967d150d8ddce452ca38d9d283b5ed0a4693fecd86a8819elfMirai
2025-10-18 15:45:26e827115ddaece0476a81cd528961283e570eaa9339fb58b483c02630889064a0elfMirai
2025-10-18 10:06:58fc715a7ebcb71d9020169f9bd23d12f3dfeb0aa311785cb93d5725f1b2bfe5b8shMirai
2025-10-13 18:56:44dcb9ffa705448d13eb89e12d853615e8d21c429a91a60d7bd80add94d8c4bce4elfGafgyt
2025-10-13 18:54:49210b2a799c3a67f16ce82924b0d71fee35c26402130839cf6dd3aeb3c9a859d7elfGafgyt
2025-10-10 21:32:20725e6681c2ee8b785825687ecf79a3ced0bf2e9ccf283ca7f5b4efa0bb45ef0ashMirai
2025-10-10 21:32:191b37a8704c9441ad299d064a8e910ac528deb4efe1c6fb5c4478279f31828e63elfGafgyt
2025-10-10 21:32:06183cc6fc1130e68338d3673193df2d7f591d22143f5fd72875c37843553d5e1aelfGafgyt
2025-10-10 21:32:061b37a8704c9441ad299d064a8e910ac528deb4efe1c6fb5c4478279f31828e63elfGafgyt
2025-10-10 21:32:06fc762805251333e8c824f3ed52e0171d2e24f06fe527fc43f3c2eb6dad20f15eshGafgyt