URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 69.5.189.168
Firstseen:2025-11-08 15:44:26 UTC
Total malware sites :8
Online malware sites :0 (0%)
Offline Malware sites :8 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-08 15:44:38 69.5.189.168VPS-goHyxAclSBL682243AS42624 swissnetwork02- SCyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-08 15:44:40http://69.5.189.168/frost.armv5Offlineelf Ngioweb ua-wget abuse_ch
2025-11-08 15:44:40http://69.5.189.168/frost.x86_64Offlineelf mirai ext Ngioweb ua-wget abuse_ch
2025-11-08 15:44:39http://69.5.189.168/frost.armv6Offlineelf Ngioweb ua-wget abuse_ch
2025-11-08 15:44:38http://69.5.189.168/frost.armv7Offlineelf Ngioweb ua-wget abuse_ch
2025-11-08 15:44:38http://69.5.189.168/frost.mipselOfflineelf mirai ext Ngioweb ua-wget abuse_ch
2025-11-08 15:44:38http://69.5.189.168/frost.aarch64Offlineelf mirai ext Ngioweb ua-wget abuse_ch
2025-11-08 15:44:38http://69.5.189.168/frost.x86Offlineelf mirai ext Ngioweb ua-wget abuse_ch
2025-11-08 15:44:38http://69.5.189.168/frost.mipsOfflineelf ua-wget abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-12 01:32:583f2c0e2becb201a5b2cd23b66deaa39b78fbea6cdc64e539edb442b99f5373d4elfNgioweb
2025-11-12 01:13:191bb57d84b79bdca142f788f2317f6afa1f8071386ac4febc7529214ed995e964elfNgioweb
2025-11-12 00:59:2507ddef2fde289218f356264bdf1d4409ffa44168c8e98c03ae3c5015ed62fbb4elfNgioweb
2025-11-12 00:58:2676e670a4333b77d5f69f0a51440618974bfb545309d57d00e6ca847e85631c86elfNgioweb
2025-11-12 00:43:09eeac99d3cb2e9e9c6c030c9964afccc0886688a0390a7849994146ac0c9604daelfNgioweb
2025-11-12 00:27:16cc5dfc104697e85043a20833fc7928418e8a7321b7b6368b37632fd13b1ec4faelfNgioweb
2025-11-11 23:54:288a9b339fd801c708cb76a8204ccce25fa81d06703371c28f832220426886aaf9elf 
2025-11-11 23:41:59ddebe545870ecfe87f0d403a1a1bbf0343c4b9ea4e727e2bdb1915f966658435elfNgioweb
2025-11-08 15:44:40966770e3938bb350119a960948a15421d9c6e0944c4d49f5aa631d3bd9fee703elfNgioweb
2025-11-08 15:44:40a85c562d0b13602adfad63635f895ba1fcd8f4780121f7f98febc10fbfba1819elfMirai
2025-11-08 15:44:39f08d8c43beedbc8d45ea133b44dd09e13d80d725846eac7615141dee9064907eelfNgioweb
2025-11-08 15:44:38d0ca62e68e235aca958e3877ae7ed505c5667207c95d34907bc806e5ffa0b21belfNgioweb
2025-11-08 15:44:388758eddd99d34eae170f69fe5c58231a546fef0f56a7e30eefac59ef10ca906belfMirai
2025-11-08 15:44:387997eca9041eb31e0264e9273d28e3b672f6f6cb206919ea1167610cfa601f93elfMirai
2025-11-08 15:44:38296d6af5b711aada05ec72d517af8b677c32d4f894fda2934ad5289b7f671619elfMirai
2025-11-08 15:44:3816c193e0951e4649d08312856bba21449eeb11068838c6079d77bf88cb37086felf