URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 61.183.16.127
Firstseen:2024-11-27 19:20:07 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-11-27 19:21:41 61.183.16.127Not listedAS4134 CHINANET-BACKBONE- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-11-27 19:21:41http://61.183.16.127:14417/help.scrOnlinecensys CoinMiner exe help.scr iframe scr NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-06-30 16:43:393b16957b3f9918adc641f64d960dc88303299a232196b9034e4944034c3f6f04exe 
2025-01-12 15:29:08d38fcf6fa72d71e5cec609f2015bcbcbc00e7cd045a9f4615b4bab12172cb1c1exe  
2025-01-01 07:53:3012c624331c002b641a4b2a293075aa89a52b8e7638b1d42512490280de4567e9exe CoinMiner
2024-12-16 02:00:16dc8a706ee154cd589e7c92fda2511902e3f9abac2147d81f61a530cf27863eb1exe  
2024-11-27 19:21:38d6350d8a664b3585108ee2b6f04f031d478e97a53962786b18e4780a3ca3da60exeCoinMiner