URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 64.89.163.118
Firstseen:2026-03-27 07:08:05 UTC
Total malware sites :16
Online malware sites :16 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-03-27 07:32:23 UTC
Oldest active malware site :2026-03-27 07:08:10 UTC (Age: 1 day, 0 hours, 46 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-27 07:08:10 64.89.163.118SBL692143AS401626 NETIFACE-TORONTO- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-27 07:32:23http://64.89.163.118/californiaOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:23http://64.89.163.118/coloradoOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:23http://64.89.163.118/connecticutOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:23http://64.89.163.118/alaskaOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:23http://64.89.163.118/floridaOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:23http://64.89.163.118/georgiaOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:23http://64.89.163.118/illinoisOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:21http://64.89.163.118/delawareOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:21http://64.89.163.118/indianaOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:21http://64.89.163.118/idahoOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:21http://64.89.163.118/arkansasOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:21http://64.89.163.118/alabamaOnlineelf gafgyt ext ua-wget NDA0E
2026-03-27 07:32:16http://64.89.163.118/hawaiiOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:32:16http://64.89.163.118/iowaOnlineelf gafgyt ext ua-wget NDA0E
2026-03-27 07:32:16http://64.89.163.118/arizonaOnlineelf mirai ext ua-wget NDA0E
2026-03-27 07:08:10http://64.89.163.118/cat.shOnlinegafgyt ext script geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-27 07:32:23794aaf6fa3e6e1170fe1ee1ab3ba99836d46753fb00b31564629ef7f18a91160elfMirai
2026-03-27 07:32:23a7359b810b45f7bb0fcb56a5da5dae41f9c65c7a4c4e5fc0267ffb5a26756c19elfMirai
2026-03-27 07:32:2327111421f6310cf286aa062d6f6c296a87345d61fdf8db6238092f1b0751662belfMirai
2026-03-27 07:32:232b6febb43bf9a1eadb08c6910276f7192b3e9c8ffb1fcbdb99770657681a3999elfMirai
2026-03-27 07:32:234bafd0db45b44a978092247b4178e3775ae19153f7c6d981fb7780d9b0d8e82aelfMirai
2026-03-27 07:32:2346831dae03c26030c63b02df4d7aa4e0bbf403d2a07590fca5bf20d1adeba246elfMirai
2026-03-27 07:32:2398c01d760ac3efcd9994fe893165baf552d7f9ab694557907690864dc263489eelfMirai
2026-03-27 07:32:21bcda6a09f766b4e12a493da81cd7680296cf2b74b8eb99f45be5e9136fa7b433elfMirai
2026-03-27 07:32:218062f4d71cf4338aa54950270d18fdeb5b3064fa498c2e944f32f5ded6d8f284elfMirai
2026-03-27 07:32:2163ca83fdf2cda2de3b68672cf07128a9ad822c6a255342d0cc1ef1767532569eelfMirai
2026-03-27 07:32:216ab1f75873cc848ba44f0280545bc605dad3631deacac546f8f67da0870b296eelfMirai
2026-03-27 07:32:19567407079429b656f934d756da30eb0d1f2b6bf3e0765c67b7095e6ea4ce316eelfGafgyt
2026-03-27 07:32:169c84623c5a9b5f79023eea9b94bba6ac2a2257a15ceb7c2f5f65b8d3cdbea0eaelfMirai
2026-03-27 07:32:160dc4d8932b1319965f4639567680d3a1d5f6fd772ae5f154ca6ef1a4b01038d2elfGafgyt
2026-03-27 07:32:163f9e3b8acf70dc1fc178cdecd755eb9cdb8f8367e2a8ec884aa181932392dce3elfMirai
2026-03-27 07:08:0960f401afeb6054e531916adb8118df45fcd7d4c1d166ac28197c67ecba2ba60cshGafgyt