URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 77.239.124.108
Firstseen:2026-08-15 15:46:04 UTC
Total malware sites :17
Online malware sites :1 (6%)
Offline Malware sites :16 (94%)
Newest active malware site :2026-08-22 07:02:07 UTC
Oldest active malware site :2026-08-22 07:02:07 UTC (Age: 1 day, 1 hours, 20 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-08-15 15:46:06 77.239.124.108Not listedAS198364 BANATSYNC-SRL- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-08-22 07:02:07http://77.239.124.108/atomic/main_x86_64Onlinecowrie honeypot mirai ext YaRi78
2026-08-20 06:21:31http://77.239.124.108/atomic/atomic.shOfflineelf iot HoneyLabs
2026-08-17 05:37:38http://77.239.124.108/iran.sh4Offlineelf ua-wget abuse_ch
2026-08-17 05:37:37http://77.239.124.108/iran.mipselOfflineelf ua-wget abuse_ch
2026-08-17 05:37:35http://77.239.124.108/iran.i486Offlineelf ua-wget abuse_ch
2026-08-17 05:37:35http://77.239.124.108/iran.m68kOfflineelf ua-wget abuse_ch
2026-08-17 05:37:34http://77.239.124.108/iran.mipsOfflineelf ua-wget abuse_ch
2026-08-17 05:37:34http://77.239.124.108/iran.armv4lOfflineelf ua-wget abuse_ch
2026-08-17 05:37:33http://77.239.124.108/iran.armv7lOfflineelf ua-wget abuse_ch
2026-08-17 05:37:33http://77.239.124.108/iran.sparcOfflineelf ua-wget abuse_ch
2026-08-17 05:37:32http://77.239.124.108/iran.armv5lOfflineelf ua-wget abuse_ch
2026-08-17 05:37:30http://77.239.124.108/iran.armv6lOfflineelf ua-wget abuse_ch
2026-08-17 05:37:29http://77.239.124.108/iran.x86_64Offlineelf ua-wget abuse_ch
2026-08-17 05:37:23http://77.239.124.108/iran.powerpcOfflineelf ua-wget abuse_ch
2026-08-17 05:37:22http://77.239.124.108/iran.aarch64Offlineelf ua-wget abuse_ch
2026-08-17 05:37:21http://77.239.124.108/iran.arcOfflineelf ua-wget abuse_ch
2026-08-15 15:46:06http://77.239.124.108/cat.shOfflinescript geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-08-22 07:02:075d5fd1339b8c8013cf65496e9c2686d9e75724bdbdb7a499c5292d8228e70abdelfMirai
2026-08-15 15:46:067824e906e6bc2fe40b62b7fed3990103dd894ac0e27367ac4509eb9e2209dbcfsh