URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.231.222.192
Firstseen:2025-11-13 01:12:05 UTC
Total malware sites :14
Online malware sites :0 (0%)
Offline Malware sites :14 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-13 01:12:08 91.231.222.192Not listedAS208191 GoHost- IRyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-13 13:09:27http://91.231.222.192/cOfflinesh BlinkzSec
2025-11-13 13:09:26http://91.231.222.192/cnOfflinesh BlinkzSec
2025-11-13 13:09:26http://91.231.222.192/dvrOfflinesh BlinkzSec
2025-11-13 13:09:26http://91.231.222.192/sepOfflinesh BlinkzSec
2025-11-13 13:08:26http://91.231.222.192/arm5OfflineDEU elf geofenced BlinkzSec
2025-11-13 13:08:26http://91.231.222.192/sh4Offlineelf BlinkzSec
2025-11-13 13:08:26http://91.231.222.192/ppcOfflineelf BlinkzSec
2025-11-13 13:08:26http://91.231.222.192/mpslOfflineelf BlinkzSec
2025-11-13 13:08:26http://91.231.222.192/arm7Offlineelf BlinkzSec
2025-11-13 13:08:25http://91.231.222.192/zOfflineelf BlinkzSec
2025-11-13 13:08:25http://91.231.222.192/x86Offlineelf BlinkzSec
2025-11-13 13:08:25http://91.231.222.192/arcOfflineelf BlinkzSec
2025-11-13 03:01:11http://91.231.222.192/armOffline32-bit elf mirai ext Mozi ext threatquery
2025-11-13 01:12:08http://91.231.222.192/mipsOfflineelf gafgyt ext geofenced mips ua-wget USA botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-22 01:28:30640038bdadf9079adf1ab02bfaa8956d5e6c9e3ee2acdcfbd831608ed5eb13efelfGafgyt
2025-11-13 03:01:114bf5fcd4f784c893332080af1716466818133d2778085d169339afa3fe1b7b2belfMirai
2025-11-13 01:12:0899bb1d3912240ba890ae97f42e3e1310e0b657a4f588bc19a46090abccf4a0ecelfGafgyt