URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 8.217.198.214
Firstseen:2025-11-27 18:22:05 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-27 18:25:01 8.217.198.214Not listedAS45102 ALIBABA-CN-NET- HKyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-27 18:25:01http://8.217.198.214:60111/linuxOfflineelf ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-19 07:12:51803f60643e9b0c4d854ddd756922b4340cf7bc438ab00a12d9432f8041bae5ecelf 
2025-12-15 07:46:5332252a6cf311b03cdfe25ce1ba008b474369e323e41d7f99f1aebbcf129ab31belf 
2025-12-15 07:46:51e65a58a7827abbdff3c349958c83633e25adf8217048e0cb4400c1b13ebd4edfelf 
2025-12-05 16:42:40d1886b189474b02467ed2845df0938cec9785e99c3d4b04e0b7de3cafbee4182elf 
2025-11-27 18:25:0111370d218430a0bdb2b584eb4181c21bd2abe9958ba639c017caf04ec019d117elf