URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 91.92.241.59
Firstseen:2025-11-30 01:59:04 UTC
Total malware sites :28
Online malware sites :26 (93%)
Offline Malware sites :2 (7%)
Newest active malware site :2025-11-30 02:00:38 UTC
Oldest active malware site :2025-11-30 02:00:16 UTC (Age: 6 hours, 35 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-30 01:59:04 91.92.241.59SBL686267AS214943 RAILNET- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-30 02:02:05http://91.92.241.59/wget.shOfflinegeofenced sh ua-wget USA botnetkiller
2025-11-30 02:00:38http://91.92.241.59/bizy.mpslsOnlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:34http://91.92.241.59/bizy.mipssOnlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:23http://91.92.241.59/bizy.mips64Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:20http://91.92.241.59/odin.armOnlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:20http://91.92.241.59/bizy.riscvOnlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:19http://91.92.241.59/bizy.mpsl64Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:19http://91.92.241.59/bizy.x86Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:19http://91.92.241.59/bizy.arm5Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:19http://91.92.241.59/bizy.x64Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:19http://91.92.241.59/bizy.arm7Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:19http://91.92.241.59/bizy.arm6Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:18http://91.92.241.59/bizy.arm8Onlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:18http://91.92.241.59/bizy.mipsOnlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:18http://91.92.241.59/bizy.mpslOnlineelf geofenced ua-wget USA botnetkiller
2025-11-30 02:00:18http://91.92.241.59/odin.mipsOnlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.x86Onlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.arm5nOnlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.arm6Onlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.x64Onlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.m68kOnlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.sh4Onlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.ppcOnlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.arm7Onlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:17http://91.92.241.59/odin.mpslOnlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:16http://91.92.241.59/odin.spcOnlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 02:00:16http://91.92.241.59/odin.arm5Onlineelf geofenced mirai ext ua-wget USA botnetkiller
2025-11-30 01:59:04http://91.92.241.59/curl.shOfflinegeofenced sh ua-wget USA botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-30 02:00:38d5084342fb3caaad185e65e1665b69f5f4436caf22e9a7bce275479827e7f9c0elf 
2025-11-30 02:00:348773f1853d7a837ff6bc07f5839a668166f2311e0cf6e507086cc403471948b8elf 
2025-11-30 02:00:23fbdcf7a6a53daba22ec7bc70482fdb81e9597d8ae0cde9031b197f9f49fd44ddelf 
2025-11-30 02:00:200768380847fec204052caea7d521b23d739ee8fedbc23831bf2549bae3fb03deelfMirai
2025-11-30 02:00:2096016d9533b9c4ac61d86048f73ad47e815d689c7955703dcea5abcb4553ccf1elf 
2025-11-30 02:00:19f122cfe19922d2a8e9c80d11acb04ed68b1dc30ab72d20fa99eca87bbb9ff979elf 
2025-11-30 02:00:19da3e18e3ef495fb7983a2357550d64833b22ab3c4d93d17ac62b7a5d76adee86elf 
2025-11-30 02:00:197469dee5a6679cd1b1293c38a1ed1c7800381936df68c87739786541f607ba60elf 
2025-11-30 02:00:191d71d8dd402e9cff4e742db2b32ad9e29925f19624f5168cb2419301e74b1b9belf 
2025-11-30 02:00:183d6f8bc6d911441bac88de85f9b6270b36fa6e4206f11b5f8bf39ca03bb8a264elf 
2025-11-30 02:00:1834ec04f0ab17549a20bd7fb257497059e087cd64be342b483a72a2ca64ddd20celf 
2025-11-30 02:00:184dfc23150298b0236500ebaa09bffa740238c3db5597e43c77244e30195f25dbelf 
2025-11-30 02:00:1816ebf82f00bc0105348c208b7a2b2fcf9eb775e7adc23bf2744c001bf9b15fc1elf 
2025-11-30 02:00:18766a44d44822cfbb7f163219868b8f08f6654acd3a386a7d7fc52ecd9924fef7elf 
2025-11-30 02:00:175a7827d9681297873e4fbc739522260acd2734824add84af2744248acf661a60elfMirai
2025-11-30 02:00:17893cd4107f8be6a0f86d1dbf376352a029700c64b41a6cb69b47e4289d11bca1elfMirai
2025-11-30 02:00:17d89b9aa7f0ac337077c5614d1d8321d1a0dff5280560bde0a8339c0dba0abd5delfMirai
2025-11-30 02:00:17c3d826404b0e9fbc0382b9b1a871acf72cda3f2f81b5306cd3b9f8741d9d4c27elfMirai
2025-11-30 02:00:1742c98a7aaed9dfdb48a02009c3ef41c71bf0e6c3a8d5d3b9bab1bae6d8799d96elfMirai
2025-11-30 02:00:1749bdea75a582c656e0b7c07fcafbd9d3ce01bae6c7802cc87cb2b9419c89640celfMirai
2025-11-30 02:00:1738f94df99e0a5ef8257dc20350f75bd3f5b9452388acf68bd16c90fa28adc3adelfMirai
2025-11-30 02:00:17bec77d584ebd3438d6cc13880e26ed059392e0633937e0de6409620caf683cfdelfMirai
2025-11-30 02:00:1728d1f0ec378ee8de8fb6a2c4b7513d01b551990bd072f62cd381c38bb5d0a5b1elfMirai
2025-11-30 02:00:17e439140f9ab57169b1821f08acbf095ce275c3d4e3107b4d52da9179c3e17661elfMirai
2025-11-30 02:00:1623699b08a3a0ec5228028064a2ee8efc12e9f90102a07b858116df90241624a1elfMirai
2025-11-30 02:00:163ccec93311c41cc3a813b5762e249706c4cc3fd2c04894585300e05221268a01elfMirai