URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.188.254.21
Firstseen:2024-12-27 14:36:04 UTC
Total malware sites :47
Online malware sites :0 (0%)
Offline Malware sites :47 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-27 14:36:06 91.188.254.21Not listedAS15440 Baltneta- LTyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-01-18 15:58:33http://91.188.254.21/oops/loki.ppcOfflineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.mpslOfflineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.x86Offlineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.arm6Offlineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.arm4Offlineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.arm5Offlineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.mipsOfflineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.x86_64Offlineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.m68kOfflineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.arm7Offlineelf NDA0E
2025-01-18 15:58:33http://91.188.254.21/oops/loki.spcOfflineelf NDA0E
2025-01-08 18:46:04http://91.188.254.21:8080/oops/Kloki.arm7Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:45:07http://91.188.254.21:8080/oops/Kloki.arm4Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:44:05http://91.188.254.21:8080/oops/Kloki.x86Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:44:05http://91.188.254.21:8080/oops/Kloki.m68kOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:43:05http://91.188.254.21:8080/oops/Kloki.mipsOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:43:05http://91.188.254.21:8080/oops/Kloki.ppcOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:43:05http://91.188.254.21:8080/oops/Kloki.arm6Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:43:05http://91.188.254.21:8080/oops/Kloki.arm5Offlinebotnet elf LZRD NDA0E
2025-01-08 18:43:05http://91.188.254.21:8080/oops/Kloki.spcOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:43:05http://91.188.254.21:8080/oops/Kloki.x86_64Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:43:05http://91.188.254.21:8080/oops/Kloki.mpslOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:38:05http://91.188.254.21/oops/Kloki.ppcOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:38:05http://91.188.254.21/oops/Kloki.arm6Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:38:05http://91.188.254.21/oops/Kloki.mipsOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.arm5Offlinebotnet elf LZRD NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.spcOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.mpslOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.arm4Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.x86Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.x86_64Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.m68kOfflinebotnet elf LZRD mirai ext NDA0E
2025-01-08 18:37:05http://91.188.254.21/oops/Kloki.arm7Offlinebotnet elf LZRD mirai ext NDA0E
2025-01-04 08:20:08http://91.188.254.21/Kloki.mpslOfflineelf mirai ext abuse_ch
2025-01-04 08:20:08http://91.188.254.21/Kloki.arm7Offlineelf mirai ext abuse_ch
2025-01-04 08:20:08http://91.188.254.21/Kloki.m68kOfflineelf mirai ext abuse_ch
2025-01-04 08:20:08http://91.188.254.21/Kloki.arm5Offlineelf mirai ext abuse_ch
2025-01-04 08:19:10http://91.188.254.21/Kloki.x86Offlineelf mirai ext abuse_ch
2025-01-04 08:19:10http://91.188.254.21/Kloki.mipsOfflineelf mirai ext abuse_ch
2025-01-04 08:19:10http://91.188.254.21/Kloki.arm4Offlineelf mirai ext abuse_ch
2025-01-04 08:19:10http://91.188.254.21/Kloki.ppcOfflineelf mirai ext abuse_ch
2025-01-04 08:19:10http://91.188.254.21/Kloki.x86_64Offlineelf mirai ext abuse_ch
2025-01-04 08:19:10http://91.188.254.21/Kloki.arm6Offlineelf mirai ext abuse_ch
2025-01-04 08:19:10http://91.188.254.21/Kloki.spcOfflineelf mirai ext abuse_ch
2025-01-04 04:01:06http://91.188.254.21/wget.shOfflinegafgyt ext mirai ext cesnet_certs
2024-12-27 15:06:04http://91.188.254.21/mpslOfflineelf mirai ext Gandylyan1
2024-12-27 14:36:06http://91.188.254.21/mipsOffline32-bit elf mirai ext threatquery

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-01-08 18:46:0476f480bb5d3b4321c07669e00e4d64dbefaa08cb5be971eb42c35add03deabc7elfMirai
2025-01-08 18:45:0784a616beb7ec6f1461fd1228ba8f629dc2b9c1d45e9cb26395e9ca7338dfc871elfMirai
2025-01-08 18:44:0576f4346fd91acdf7b9c37ba5738afb215fcc793c02ef46df8a22355fedb91e01elfMirai
2025-01-08 18:44:0598eb4c8c5edf1ea00cbf075b2845b28f8746c93844a03e01f6ba5d9255f932ffelfMirai
2025-01-08 18:43:05bebb0ff043cb40ec2fc9f1e6c01bfa53aa8e063c4271986497abb2646708d837elfMirai
2025-01-08 18:43:05192dc6e6726aaa9cce13eaaf812b070d7aa9b4824c2b1dee17e680e3d75284f7elfMirai
2025-01-08 18:43:0503d0cc1607db3d49d7658c9f00e097a2f03b5d3ba682f0454777acc7f5e189d1elfMirai
2025-01-08 18:43:058d6e4a2a63413d902527fcf5e8fe5224af17fa0b73621936fb21c8e8fc5f47dfelf 
2025-01-08 18:43:05954b58091fd10e8b40909cf411f1e203fed9f7fce39764facf29c2beb44add30elfMirai
2025-01-08 18:43:05dfa0c95348765c1b6347a5cd007cfe59e7208b3787bf779e6ea2e47d407f6fe9elfMirai
2025-01-08 18:43:059ed7c3f041272b98d202b68cecb44e5926947df78d49f844cc40c561cb03f734elfMirai
2025-01-08 18:38:05954b58091fd10e8b40909cf411f1e203fed9f7fce39764facf29c2beb44add30elfMirai
2025-01-08 18:38:05dfa0c95348765c1b6347a5cd007cfe59e7208b3787bf779e6ea2e47d407f6fe9elfMirai
2025-01-08 18:38:059ed7c3f041272b98d202b68cecb44e5926947df78d49f844cc40c561cb03f734elfMirai
2025-01-08 18:37:0576f480bb5d3b4321c07669e00e4d64dbefaa08cb5be971eb42c35add03deabc7elfMirai
2025-01-08 18:37:058d6e4a2a63413d902527fcf5e8fe5224af17fa0b73621936fb21c8e8fc5f47dfelf 
2025-01-08 18:37:0503d0cc1607db3d49d7658c9f00e097a2f03b5d3ba682f0454777acc7f5e189d1elfMirai
2025-01-08 18:37:05bebb0ff043cb40ec2fc9f1e6c01bfa53aa8e063c4271986497abb2646708d837elfMirai
2025-01-08 18:37:0584a616beb7ec6f1461fd1228ba8f629dc2b9c1d45e9cb26395e9ca7338dfc871elfMirai
2025-01-08 18:37:0576f4346fd91acdf7b9c37ba5738afb215fcc793c02ef46df8a22355fedb91e01elfMirai
2025-01-08 18:37:05192dc6e6726aaa9cce13eaaf812b070d7aa9b4824c2b1dee17e680e3d75284f7elfMirai
2025-01-08 18:37:0598eb4c8c5edf1ea00cbf075b2845b28f8746c93844a03e01f6ba5d9255f932ffelfMirai
2025-01-08 03:57:27e8423ae37bbde2bed7aea0527d6b1b962f1cb4eeeb3651693b59bb881b874a52sh 
2025-01-07 21:20:47d480095c03673777a804039119b9d90fac1e62e45ade839be9f490f124424d44sh 
2025-01-07 18:29:485f73aee2d6b292aa93d9a743e4e2a46202b360c8ef74bbd29424d326516d1249shGafgyt
2025-01-04 08:20:08e5a11ff5b01497755c01ae790c9758376b8abc6ef805ae142a326089728d5df9elfMirai
2025-01-04 08:20:08eb3e694a5a22497585690a3c97acfdf0d6788968538cd0a05dc30fe3599aa79belfMirai
2025-01-04 08:20:086e15ca0d44f9755e25d43b727e0f955dc8fc8047db4d0fc8c180a7f1f75a7adbelfMirai
2025-01-04 08:20:08af697660b27a6a01c5e5c1be4cdfd946a8dd6595d221acc7e5a07cbf68376c50elfMirai
2025-01-04 08:19:09a0a114e9f90a3b28dfb45c574e0dbfee7ecc2eee8802550088c635aff6f5ee98elfMirai
2025-01-04 08:19:094807c962e66f0142d8cec0d2253e5324ddf69f76c3674466ac5ca172ed03174felfMirai
2025-01-04 08:19:09b1e9744ae47146393b87783e6d9d560d4396fe50b56961903d4706697d115164elfMirai
2025-01-04 08:19:090fcf14ca363a57d61610bfc67af3ddbb87f1635e6d456becb340e4428ca60df2elfMirai
2025-01-04 08:19:09e9f6e4ca27e0b00e3abb8d2064c14e919b2ca017ebd4f8f014863bbe824bd6ebelfMirai
2025-01-04 08:19:0937e1cf2f265d16edcfec29c618de091d35b61233e8d2eb8a9baa42ae3c08c45eelfMirai
2025-01-04 08:19:098a1ff3a98c8c7685707bbbe14e3c21f4236687a069984c1d44ea47d40ba8f18felfMirai
2025-01-04 04:01:06c71b8d66ac2f86177e48df856681cfb53528f1613ca1dae67593a705d7e0ad19shMirai
2025-01-03 22:44:38a2ebf0a7abbe158e061619ba17170119925b8fd420b0c0ff76cb30c3cd5bb6fcelfMirai
2025-01-03 19:19:53b5340d2f2711b0df392187b8f40cd80a464c5cc6df8b6ff79fd9c212234a3227elfMirai
2024-12-27 20:02:002e9958508e56357ca8d0e43bf843a93df3c315d229cb1c4d82261876c90e7afaelfMirai
2024-12-27 17:44:052484754793dfc38e0f5508d6b01b78b0fcaaecbb93be0ee17a9c6604a5dfbaa5elfMirai
2024-12-27 15:06:046f50c1f79ac90b77d71393dbefb44d384bf8a5d377046a0294f6dc7130377de7elfMirai
2024-12-27 14:36:05b14568287fc9faa8ab1ddb505a826062307f78fd14a2e3cbe73628a52c10ae9celfMirai