URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 64.49.14.19
Firstseen:2024-12-18 07:17:04 UTC
Total malware sites :26
Online malware sites :0 (0%)
Offline Malware sites :26 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-18 07:17:06 64.49.14.19Not listedAS396356 LATITUDE-SH- SGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-12-25 11:40:07http://64.49.14.19/sh4Offlineelf gafgyt ext NDA0E
2024-12-25 11:39:08http://64.49.14.19/4gOfflinemirai ext sh NDA0E
2024-12-25 11:39:08http://64.49.14.19/toOfflinemirai ext sh NDA0E
2024-12-25 11:39:08http://64.49.14.19/wget.shOfflinemirai ext sh NDA0E
2024-12-25 11:39:08http://64.49.14.19/idcOfflinemirai ext sh NDA0E
2024-12-25 11:39:08http://64.49.14.19/tlrOfflinemirai ext sh NDA0E
2024-12-25 11:39:08http://64.49.14.19/nucOfflinemirai ext sh NDA0E
2024-12-25 11:39:08http://64.49.14.19/curl.shOfflinemirai ext sh NDA0E
2024-12-25 11:39:08http://64.49.14.19/x86Offlineelf mirai ext NDA0E
2024-12-25 11:39:08http://64.49.14.19/arm7Offlineelf mirai ext NDA0E
2024-12-25 11:39:08http://64.49.14.19/ppcOfflineelf mirai ext NDA0E
2024-12-25 11:39:07http://64.49.14.19/arcOfflineelf mirai ext NDA0E
2024-12-25 11:39:07http://64.49.14.19/mpslOfflineelf gafgyt ext NDA0E
2024-12-25 11:39:07http://64.49.14.19/arm5Offlineelf mirai ext NDA0E
2024-12-25 11:39:05http://64.49.14.19/dlr.arm7Offlineelf NDA0E
2024-12-25 11:39:05http://64.49.14.19/dlr.arm5Offlineelf NDA0E
2024-12-25 11:39:05http://64.49.14.19/dlr.mipsOfflineelf NDA0E
2024-12-25 11:39:05http://64.49.14.19/dlr.mpslOfflineelf NDA0E
2024-12-25 11:39:05http://64.49.14.19/ftpget.shOfflinemirai ext sh NDA0E
2024-12-25 11:39:05http://64.49.14.19/dlr.ppcOfflineelf NDA0E
2024-12-25 11:39:05http://64.49.14.19/tftp.shOfflinemirai ext sh NDA0E
2024-12-25 11:39:05http://64.49.14.19/dlr.armOfflineelf NDA0E
2024-12-25 11:39:05http://64.49.14.19/dlr.sh4Offlineelf NDA0E
2024-12-25 10:54:05http://64.49.14.19/mipsOffline32-bit elf gafgyt ext threatquery
2024-12-25 10:54:05http://64.49.14.19/armOffline32-bit elf mirai ext threatquery
2024-12-18 07:17:06http://64.49.14.19/fxOfflinebash mirai ext sh ua-wget Ash_XSS_1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-12-25 11:40:07e98741fe8f43cd1ae807d0494af883631447040ade24670bbd45afe6eda24140elfGafgyt
2024-12-25 11:39:08c8e95910c3019666f111301f11633bf8c28e2b3737eb87615a396dd41ca7e520elfMirai
2024-12-25 11:39:08fdf1e731ef1ab95b8e50a3b0c2456902b77e19f5b1c55fe485bac3c3f97f690csh 
2024-12-25 11:39:08e5fc851b0e3ed667cbd7e2a1452450eccd6f6ce99e086c4a06ce7ed665944796sh 
2024-12-25 11:39:0839c4bb37a60b12390ad69d052bfc7969267033bf186aed00dbb36b75d4d7529csh 
2024-12-25 11:39:0805e5fb6c5eda8ad555044f7caa66e17348a8f0aef00cc9031113c902c22d5df5sh 
2024-12-25 11:39:0819df9599c35847d7ebd4aeccbce3f26a4fee6a782b62eb48e62177c4c373922dsh 
2024-12-25 11:39:08f3f014794a53d1c884951eda59c8436158b6ef0944952a5a00b9214597d1d26dsh 
2024-12-25 11:39:0845dc98809917b1567dbb7b995494177682a247ddd60ee3554378c5dc39c7f20csh 
2024-12-25 11:39:08d2ea0eed1f82458ed76a956ca3fd1f72d1c1e29b40a6118d1e5f1e6d78418077elfMirai
2024-12-25 11:39:084a7ce3ce807ef1d303c65bf4a2cea3bb8ed5456c5045e7a25ca6ef4dee76d446elfMirai
2024-12-25 11:39:0718c99e6db38118a4d50a0bca8dd475f700d3ff172a73fb6a48bdd599d4abae95elfGafgyt
2024-12-25 11:39:073d75958b2fb71b541ffa1a59de68ac6293dc7066470274b602cd4d1db96d0040elfMirai
2024-12-25 11:39:070b051fb3621726c4525a268f2bb2c12456cc238b0b301c249feb2872177ae517elfMirai
2024-12-25 10:54:054fc73b02bd0cc4d44ee8da03ce5ab8b74fb67409fb223c3f36b06dc22dc0dd74elfGafgyt
2024-12-25 10:54:052f66b28645b910c0fcb7a751e9a0dad86fd2be825d07f45dd6ab086ec2eeafc0elfMirai
2024-12-18 07:17:06b5bab0247bd15c2feed7d31a2f6bbb9ac0faecf8855def5dbfa29d82a2b2d312sh