URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 82.221.139.173
Firstseen:2026-01-10 12:56:05 UTC
Total malware sites :25
Online malware sites :12 (48%)
Offline Malware sites :13 (52%)
Newest active malware site :2026-01-11 17:04:14 UTC
Oldest active malware site :2026-01-11 17:02:16 UTC (Age: 10 hours, 35 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-10 12:56:17 82.221.139.173server.sashanoelle.nlNot listedAS50613 ThorDC-AS- ISyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-11 17:04:14http://82.221.139.173:49180/bins/win.arm6Onlineelf mirai ext tolisec
2026-01-11 17:04:14http://82.221.139.173:49180/bins/win.armOnlineelf mirai ext tolisec
2026-01-11 17:03:16http://82.221.139.173:49180/bins/win.m68kOnlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.arm7Onlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.mipsOnlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.mpslOnlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.ppcOnlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.sh4Onlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.arm5Onlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.x86Onlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.spcOnlineelf mirai ext tolisec
2026-01-11 17:02:16http://82.221.139.173:49180/bins/win.x86_64Onlineelf mirai ext tolisec
2026-01-10 13:40:05http://82.221.139.173:49180/based.shOfflinegeofenced opendir sh ua-wget USA botnetkiller
2026-01-10 12:56:29http://82.221.139.173:49180/bins/old.arm5Offlineelf mirai ext tolisec
2026-01-10 12:56:29http://82.221.139.173:49180/bins/old.spcOfflineelf mirai ext tolisec
2026-01-10 12:56:29http://82.221.139.173:49180/bins/old.ppcOfflineelf mirai ext tolisec
2026-01-10 12:56:29http://82.221.139.173:49180/bins/old.mpslOfflineelf mirai ext tolisec
2026-01-10 12:56:29http://82.221.139.173:49180/bins/old.armOfflineelf mirai ext tolisec
2026-01-10 12:56:29http://82.221.139.173:49180/bins/old.sh4Offlineelf mirai ext tolisec
2026-01-10 12:56:29http://82.221.139.173:49180/bins/old.x86Offlineelf mirai ext tolisec
2026-01-10 12:56:28http://82.221.139.173:49180/bins/old.arm7Offlineelf mirai ext tolisec
2026-01-10 12:56:27http://82.221.139.173:49180/bins/old.mipsOfflineelf mirai ext tolisec
2026-01-10 12:56:27http://82.221.139.173:49180/bins/old.arm6Offlineelf mirai ext tolisec
2026-01-10 12:56:27http://82.221.139.173:49180/bins/old.m68kOfflineelf mirai ext tolisec
2026-01-10 12:56:17http://82.221.139.173:49180/bins/old.x86_64Offlineelf mirai ext tolisec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-11 17:04:144aa6b2c97c38699f032273700f5a0e66bdf83e287bd9d2c6103c02362423ae02elfMirai
2026-01-11 17:04:145bf2a5c8ea7d0042377193ad7ad8872d1c8b3e419f018641b38e75888d6f0ff1elfMirai
2026-01-11 17:03:15ccfd32a377975deb88f554a0e81dc091f09624ea85c1523284f04fd66eb743b7elfMirai
2026-01-11 17:02:1623c219bce4d06111ac775ff98c6c657dd70ece2342c13ced3c766517f3c886b4elfMirai
2026-01-11 17:02:16b42a0de5b5347175e9c67e32e9059891bc128b545c64c3e442ac989dd9ed481delfMirai
2026-01-11 17:02:1656181d452eb432f9c90b5b57e27acbf43fd9578d00c82f6b91ba8d1110dd1a0felfMirai
2026-01-11 17:02:1640ea414584c59c8cba19975229a04f9b38d65846acee9dde48c8ee93e4aae157elfMirai
2026-01-11 17:02:16797b3ff04087e098030787e8885ab33bf812cdba4d24589a8e0c9cac6d0196bfelfMirai
2026-01-11 17:02:16f05cf50c7c3c92a68c3db6a6aaf74ade7db799c78cdb166f2d9b4a3bd41b01e7elfMirai
2026-01-11 17:02:16a8af028c1cb6164764295cbb7d9b1d193617d5a763adcb8eb99e822658adb192elfMirai
2026-01-11 17:02:160b78b918ad80ae4682785566d7248925de0f37c4976a18ff8a62b06c3dd5656belfMirai
2026-01-11 17:02:15bf87f93d0e321b85f243883b30edf61fc5af7187e31320db9d8445c10a1b0ce5elfMirai
2026-01-10 12:56:290d79738dbbe5f73416faf217280f77bbbc9e6dc21b3522938d227a9ebc454699elfMirai
2026-01-10 12:56:2950c6a2c7c77d949b851eb924264bfc6d40f1f6e145260b3f9a828c24dc1c59afelfMirai
2026-01-10 12:56:29d6f075cb006c89207f4fd393e202a3e239f9561b5faab1502467169b6fa57c62elfMirai
2026-01-10 12:56:2972e0b789e13e4c4390e88b216be7957f150120f5f194192f0b14acb21807bdbeelfMirai
2026-01-10 12:56:29d2faabf3ec023f90cee47292804cf410a53a735a9eb0e32b126f25ce49c061b9elfMirai
2026-01-10 12:56:292ca9925dd232850cf3d1f94a97b1e1b6f3b18ca003049cc8152afc360e13b70delfMirai
2026-01-10 12:56:2957a725a6b786bce7630aae16b038ac6317495137039036a8913009b0b2b60efdelfMirai
2026-01-10 12:56:27d401364fa33e4297f3b232ddd4b10c85a08c422358048e87c486c3cc75671b5belfMirai
2026-01-10 12:56:27879b53c22862b2e6f7a1663c45bc3996956127e98d08ce0b343a10674dab6852elfMirai
2026-01-10 12:56:27c740413fa8c7924bc4ca3803c6a9f7a6f9f8c34845120758a41ad802d6ebbe14elfMirai
2026-01-10 12:56:27c01bff33cc108ecefaf8616834529aa0ef6a33a66a0169ad1667ab6c468ff6c3elfMirai
2026-01-10 12:56:1603c7c37d239120b6249e71a98c0454b0c44e6800c308c6752f974acf697452faelfMirai