URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 81.70.85.113
Firstseen:2025-02-06 00:18:03 UTC
Total malware sites :25
Online malware sites :18 (72%)
Offline Malware sites :7 (28%)
Newest active malware site :2026-01-09 13:08:32 UTC
Oldest active malware site :2025-02-06 00:18:10 UTC (Age: 11 months, 9 days, 8 hours, 3 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-02-06 00:18:10 81.70.85.113Not listedAS45090 TENCENT-NET-AP- CNyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-09 13:08:32http://81.70.85.113/data/Diamorphine-master.zipOnlinezip Anonymous
2026-01-09 13:07:43http://81.70.85.113/data/connect.php.malloxOfflineelf mirai ext php Anonymous
2025-02-06 00:18:17http://81.70.85.113/tp/earm7Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:17http://81.70.85.113/backdoor/emipsOnlineelf gafgyt ext mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:17http://81.70.85.113/earmOnlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:15http://81.70.85.113/tp/earmOnlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:15http://81.70.85.113/backdoor/earm5Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:14http://81.70.85.113/tp/emipsOnlineelf gafgyt ext mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:13http://81.70.85.113/tp/ex86Offlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:13http://81.70.85.113/backdoor/earmOnlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:13http://81.70.85.113/earm7Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/backdoor/earm6Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/backdoor/earm7Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/earm6Offlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/tOfflinemirai ext opendir sh ua-wget DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/tp/earm6Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/ex86Offlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/backdoor/empslOnlineelf gafgyt ext mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:12http://81.70.85.113/tp/empslOnlineelf gafgyt ext mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:11http://81.70.85.113/dvrLockerOfflineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:11http://81.70.85.113/earm5Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:11http://81.70.85.113/emipsOnlineelf gafgyt ext mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:11http://81.70.85.113/tp/earm5Onlineelf mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:10http://81.70.85.113/empslOnlineelf gafgyt ext mirai ext opendir DaveLikesMalwre
2025-02-06 00:18:10http://81.70.85.113/backdoor/ex86Offlineelf mirai ext opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-09 13:08:3217cbca5c677d29b07760e9db6fcb8ba57e3edfa1c21bee6740664515f3a97b37zip  
2025-02-07 04:28:55bb29581c79f14d9da7048346e273c54bd8893692b67f95e93104b84a4e88ac7ashMirai
2025-02-06 00:18:17efaf599ac65b6960a2888be4b91fdb831ec7bc374d8904794ea837a47af2cd66elfMirai
2025-02-06 00:18:1779794a133e5820788924f137136348593c481966288a28273df696950c6d543aelfGafgyt
2025-02-06 00:18:1627c5412cc2036dd7b38f646f090f8b72843aaab3c2ecd70ca8d86665f3d4f1eaelfMirai
2025-02-06 00:18:1527c5412cc2036dd7b38f646f090f8b72843aaab3c2ecd70ca8d86665f3d4f1eaelfMirai
2025-02-06 00:18:151500cbdcf6c0c50472336ad9dc3a1d5d00f062b89cc25a758350c4820363455aelfMirai
2025-02-06 00:18:1479794a133e5820788924f137136348593c481966288a28273df696950c6d543aelfGafgyt
2025-02-06 00:18:1356324f2c821373066aecce69f0e0a383bd7ce536391b8fe13abdebb765cd09e9elfMirai
2025-02-06 00:18:1327c5412cc2036dd7b38f646f090f8b72843aaab3c2ecd70ca8d86665f3d4f1eaelfMirai
2025-02-06 00:18:13efaf599ac65b6960a2888be4b91fdb831ec7bc374d8904794ea837a47af2cd66elfMirai
2025-02-06 00:18:122d3482fc6ea845ffe8918e9d186fc8454091b4348feee07006ef7df8752dd6e5elfMirai
2025-02-06 00:18:12efaf599ac65b6960a2888be4b91fdb831ec7bc374d8904794ea837a47af2cd66elfMirai
2025-02-06 00:18:122d3482fc6ea845ffe8918e9d186fc8454091b4348feee07006ef7df8752dd6e5elfMirai
2025-02-06 00:18:126023efb8ca704d4345acf8e27ca320c3d16ab614bd969d3153144f56d825fe67shMirai
2025-02-06 00:18:122d3482fc6ea845ffe8918e9d186fc8454091b4348feee07006ef7df8752dd6e5elfMirai
2025-02-06 00:18:1256324f2c821373066aecce69f0e0a383bd7ce536391b8fe13abdebb765cd09e9elfMirai
2025-02-06 00:18:120331985724dc711d88b447dd2d352a1b8a9951b045dff4afb2e48895b85c73a7elfGafgyt
2025-02-06 00:18:120331985724dc711d88b447dd2d352a1b8a9951b045dff4afb2e48895b85c73a7elfGafgyt
2025-02-06 00:18:1156324f2c821373066aecce69f0e0a383bd7ce536391b8fe13abdebb765cd09e9elfMirai
2025-02-06 00:18:111500cbdcf6c0c50472336ad9dc3a1d5d00f062b89cc25a758350c4820363455aelfMirai
2025-02-06 00:18:1179794a133e5820788924f137136348593c481966288a28273df696950c6d543aelfGafgyt
2025-02-06 00:18:111500cbdcf6c0c50472336ad9dc3a1d5d00f062b89cc25a758350c4820363455aelfMirai
2025-02-06 00:18:100331985724dc711d88b447dd2d352a1b8a9951b045dff4afb2e48895b85c73a7elfGafgyt
2025-02-06 00:18:1056324f2c821373066aecce69f0e0a383bd7ce536391b8fe13abdebb765cd09e9elfMirai