URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 85.11.167.21
Firstseen:2026-04-18 01:37:04 UTC
Total malware sites :14
Online malware sites :0 (0%)
Offline Malware sites :14 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-18 01:37:14 85.11.167.21baulk-bended.northernlettings.comSBL694610AS213438 colocatel-inc- BGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-19 11:29:27http://85.11.167.21/scarOfflineelf ua-wget abuse_ch
2026-04-19 11:29:08http://85.11.167.21/x86Offlineelf ua-wget abuse_ch
2026-04-18 04:17:13http://85.11.167.21/sex.shOffline85-11-167-21 gafgyt ext sh ua-wget BlinkzSec
2026-04-18 04:17:13http://85.11.167.21/dcOffline85-11-167-21 elf gafgyt ext ua-wget BlinkzSec
2026-04-18 04:17:13http://85.11.167.21/mipsOffline85-11-167-21 elf gafgyt ext ua-wget BlinkzSec
2026-04-18 01:39:06http://85.11.167.21/m68kOfflineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:38:16http://85.11.167.21/arm61Offlineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:38:16http://85.11.167.21/586Offlineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:38:16http://85.11.167.21/dssOfflineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:38:16http://85.11.167.21/sh4Offlineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:38:16http://85.11.167.21/mipselOfflineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:38:16http://85.11.167.21/ppcOfflineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:38:16http://85.11.167.21/coOfflineelf gafgyt ext ua-wget ClearlyNotB
2026-04-18 01:37:14http://85.11.167.21/i686Offlineelf gafgyt ext ua-wget ClearlyNotB