URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91-92-241-8.cprapid.com
Domain registrar:Tucows -
Domain registration date:2019-05-16 21:16:20 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-10-21 15:44:05 UTC
Total malware sites :20
Online malware sites :0 (0%)
Offline Malware sites :20 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-21 15:44:09 91.92.241.8SBL686267AS202412 OMEGATECH-AS- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-21 15:59:10http://91-92-241-8.cprapid.com/kvariant.ppcOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:31http://91-92-241-8.cprapid.com/adbOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:31http://91-92-241-8.cprapid.com/kvariant.armOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:29http://91-92-241-8.cprapid.com/payload.xmlOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:23http://91-92-241-8.cprapid.com/kvariant.arm7Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:21http://91-92-241-8.cprapid.com/kvariant.arm5Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:21http://91-92-241-8.cprapid.com/springOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:21http://91-92-241-8.cprapid.com/kvariant.spcOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:21http://91-92-241-8.cprapid.com/kvariant.arm6Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:20http://91-92-241-8.cprapid.com/tplinkOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:20http://91-92-241-8.cprapid.com/kvariant.sh4Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:20http://91-92-241-8.cprapid.com/linkOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:20http://91-92-241-8.cprapid.com/kvariant.arcOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:20http://91-92-241-8.cprapid.com/shOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:20http://91-92-241-8.cprapid.com/vacOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:20http://91-92-241-8.cprapid.com/kvariant.x86Offlinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:13http://91-92-241-8.cprapid.com/byteOfflinebotnetdomain sh BlinkzSec
2025-10-21 15:44:11http://91-92-241-8.cprapid.com/kvariant.m68kOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:10http://91-92-241-8.cprapid.com/kvariant.mipsOfflinebotnetdomain elf mirai ext BlinkzSec
2025-10-21 15:44:09http://91-92-241-8.cprapid.com/kvariant.mpslOfflinebotnetdomain elf mirai ext BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-21 15:59:10071357ef22811f8998d8d3c00d466bd674e68dae8e9532dae4a7b84fd709f6a5elfMirai
2025-10-21 15:56:23c20082ef1b408e6cad1684866eb4131fc2a6351853f982c8bdb414c41ed66784txt  
2025-10-21 15:44:31855dc153454ecfbc18dc29fbea1d29e93be3a241b75d9c3a2fcb1321e9d4a2cbsh 
2025-10-21 15:44:31db4fd86ee3b6f8d0d115c1e0aecfcd22ec1c16194e0131c53783189d1910c019elfMirai
2025-10-21 15:44:23c5df9777e2ce06727afae5f68432642088c11b601621a9c10a9546b6bfce4527elfMirai
2025-10-21 15:44:215011b1052b3a4287b54b751a899d8c0b477e766a86096822da9f231351b57e5eelfMirai
2025-10-21 15:44:2110decd9a0932cec823aab380824de1b50a1e450e04658838d6c21a1055f97aacsh 
2025-10-21 15:44:21c5e6c54be7165302d69d98a7082c8a0dfe99f8b45926386ffd6aa2687ba38f03elfMirai
2025-10-21 15:44:21bf36063c3578accbed30ff3a1d2b857f859c5b004e050f1013dc5a725f997f18elfMirai
2025-10-21 15:44:20a394202c674f2675b60a5690dfa7854243379a66e5dec944fec429336239a7f3sh 
2025-10-21 15:44:207489d027264a55c2dd854f5a2bbe6879f6a0c9c4839d2daf097810ac8e944873elfMirai
2025-10-21 15:44:20463713a9d829a3d60d41e6c80df84b2ac33c79ea09447c3e8e62fd152e4d1c51sh 
2025-10-21 15:44:20028a0fd7dfe16a5d4bace505bed6b7820b11cff87dd42d0e371f6c2175ee4dbcelfMirai
2025-10-21 15:44:20d8053eac8cf5de22b3c331615f309228913c7118d5baa4c298227834244e8fb3sh 
2025-10-21 15:44:2020f5bac38fd073fe3b46916e783f8cfa09556ae0ab9a5968de747df33f7cf077sh 
2025-10-21 15:44:202828f2e44beb56316ae42db5d604a2ebdb8edc9bd34c3ac1ab74c6523296fe9aelfMirai
2025-10-21 15:44:13ffc06c389aee18730f939be78e9cc436e20887bce312d97ba55a424262ef11d2sh 
2025-10-21 15:44:11a8d43893e88005aca0373024e343bd619f5b33531a0a3f52a9cf625ac6106e8delfMirai
2025-10-21 15:44:10e179ccaf1197673caae04314045e8aef4e1006412d41493ff76766a951d54273elfMirai
2025-10-21 15:44:095ed95e23909a89a0bd7d335f8d208377fbecfdc45cb6e87e119376733f0ea960elfMirai