URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 72.29.46.195
Firstseen:2023-06-08 09:21:03 UTC
Total malware sites :16
Online malware sites :2 (13%)
Offline Malware sites :14 (88%)
Newest active malware site :2025-11-23 01:44:16 UTC
Oldest active malware site :2025-11-22 21:44:18 UTC (Age: 4 days, 20 hours, 52 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-06-08 09:21:28 72.29.46.195dsl-72-29-46-195.potc.netNot listedAS395107 RTI- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-23 01:44:16http://72.29.46.195:60189/bin.shOnline32-bit elf mips Mozi ext geenensp
2025-11-22 21:44:18http://72.29.46.195:60189/iOnline32-bit elf mips Mozi ext geenensp
2025-10-27 15:01:14http://72.29.46.195:49318/iOffline32-bit elf Mozi ext threatquery
2025-09-05 04:55:21http://72.29.46.195:60944/iOffline32-bit elf mips Mozi ext geenensp
2025-09-05 04:31:07http://72.29.46.195:60944/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-08-08 18:59:08http://72.29.46.195:36681/iOffline32-bit elf mips Mozi ext geenensp
2025-08-07 03:51:07http://72.29.46.195:36681/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-04-30 04:26:13http://72.29.46.195:33411/iOffline32-bit elf mips Mozi ext geenensp
2025-04-29 22:29:11http://72.29.46.195:33411/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-04-14 22:14:05http://72.29.46.195:47587/iOffline32-bit elf mips Mozi ext geenensp
2025-04-14 18:50:06http://72.29.46.195:47587/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-02-06 09:57:05http://72.29.46.195:48817/iOffline32-bit elf mips Mozi ext geenensp
2025-02-05 09:54:05http://72.29.46.195:48817/bin.shOffline32-bit elf mips Mozi ext geenensp
2025-02-04 06:36:06http://72.29.46.195:33778/iOffline32-bit elf mips Mozi ext geenensp
2024-04-04 21:17:08http://72.29.46.195:36782/iOffline32-bit elf mips Mozi ext geenensp
2023-06-08 09:21:28http://72.29.46.195:54802/Mozi.mOfflineelf Mozi ext lrz_urlhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-23 01:44:162e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6elf  
2025-11-22 21:44:182e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6elf  
2025-10-27 15:01:144293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-09-05 04:55:214293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-09-05 04:31:074293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-08-08 18:59:084293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-08-07 03:51:074293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-04-30 04:26:134293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-04-29 22:29:114293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-04-14 22:14:054293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-04-14 18:50:064293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-02-06 09:57:054293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-02-05 09:54:054293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2025-02-04 06:36:064293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2024-04-04 21:17:084293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi
2023-06-08 09:21:224293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7elfMozi