URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 92.119.159.122
Firstseen:2022-04-16 10:21:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-04-16 10:21:06 92.119.159.122vipo.justforconsummers.comNot listedAS44812 IPSERVER-RU-NET- RUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-04-16 10:21:06http://92.119.159.122/bins/CronarmOfflineDDoS Bot elf mirai ext Gandylyan1
2022-04-16 10:21:06http://92.119.159.122/bins/Cronarm5OfflineDDoS Bot elf mirai ext Gandylyan1
2022-04-16 10:21:06http://92.119.159.122/bins/Cronx86OfflineDDoS Bot elf mirai ext Gandylyan1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-04-16 10:21:063e036c11d0906bc3bf42ea2a23e21dae0aef386e61d5a1d5213f028a50b333f3elfMirai
2022-04-16 10:21:06c9704e2aaa6e3b8fc79da1e90dc020ed261209445ce5f2733324b10d685a6de3elfMirai
2022-04-16 10:21:0674b58c5812114907d127c2c0498bd7197e818ef9793450dafbc15d1705289f67elfMirai