URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 94.156.161.21
Firstseen:2023-08-01 00:23:03 UTC
Total malware sites :32
Online malware sites :0 (0%)
Offline Malware sites :32 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-08-01 00:23:04 94.156.161.21Not listedAS201183 voiptelitalia- ITyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-08-03 21:42:04http://94.156.161.21/bins/sora.m68kOffline32 elf mirai ext motorola zbetcheckin
2023-08-03 21:41:05http://94.156.161.21/bins/sora.sh4Offline32 elf mirai ext renesas zbetcheckin
2023-08-03 21:41:05http://94.156.161.21/bins/sora.arm5Offline32 arm elf mirai ext zbetcheckin
2023-08-03 21:36:05http://94.156.161.21/bins/sora.spcOffline32 elf mirai ext sparc zbetcheckin
2023-08-03 21:36:04http://94.156.161.21/bins/sora.ppcOffline32 elf mirai ext PowerPC zbetcheckin
2023-08-03 21:36:04http://94.156.161.21/bins/sora.armOffline32 arm elf mirai ext zbetcheckin
2023-08-03 20:56:04http://94.156.161.21/bins/sora.x86Offline 32-bit elf mirai ext x86-32 geenensp
2023-08-03 04:23:04http://94.156.161.21/m68kOffline32 elf mirai ext motorola zbetcheckin
2023-08-03 04:23:03http://94.156.161.21/powerpcOffline32 bashlite elf gafgyt ext mirai ext PowerPC zbetcheckin
2023-08-03 04:22:05http://94.156.161.21/i586Offline32 bashlite elf gafgyt ext intel mirai ext zbetcheckin
2023-08-03 04:22:05http://94.156.161.21/armv5lOffline32 arm bashlite elf gafgyt ext zbetcheckin
2023-08-03 04:22:05http://94.156.161.21/armv4lOffline32 arm bashlite elf gafgyt ext mirai ext zbetcheckin
2023-08-03 04:22:05http://94.156.161.21/mipselOffline32 bashlite elf gafgyt ext mips mirai ext zbetcheckin
2023-08-03 04:21:06http://94.156.161.21/i686Offline32 elf intel mirai ext zbetcheckin
2023-08-03 04:21:06http://94.156.161.21/sparcOffline32 bashlite elf gafgyt ext mirai ext sparc zbetcheckin
2023-08-03 04:21:06http://94.156.161.21/armv6lOffline32 arm bashlite elf gafgyt ext mirai ext zbetcheckin
2023-08-03 04:21:06http://94.156.161.21/sh4Offline32 bashlite elf gafgyt ext mirai ext renesas zbetcheckin
2023-08-03 04:21:06http://94.156.161.21/mipsOffline32 bashlite elf gafgyt ext mips mirai ext zbetcheckin
2023-08-03 04:16:05http://94.156.161.21/sexybins.shOffline bjornruberg
2023-08-02 05:59:04http://94.156.161.21/z0l1mxjm4mdl4jjfjf7sb2vdmv...Offline ascii geenensp
2023-08-01 21:28:04http://94.156.161.21/x86Offline 64-bit elf mirai ext x86-64 geenensp
2023-08-01 02:40:07http://94.156.161.21/x-8.6-.SNOOPYOffline 64-bit elf gafgyt ext x86-64 geenensp
2023-08-01 01:30:09http://94.156.161.21/AB4g5/Josho.mpslOffline32 elf mips mirai ext zbetcheckin
2023-08-01 01:30:09http://94.156.161.21/AB4g5/Josho.spcOffline32 elf mirai ext sparc zbetcheckin
2023-08-01 00:42:04http://94.156.161.21/AB4g5/Josho.mipsOffline32 elf mips mirai ext zbetcheckin
2023-08-01 00:42:04http://94.156.161.21/AB4g5/Josho.armOffline32 arm elf mirai ext zbetcheckin
2023-08-01 00:42:04http://94.156.161.21/AB4g5/Josho.arm6Offline32 arm elf mirai ext zbetcheckin
2023-08-01 00:42:03http://94.156.161.21/AB4g5/Josho.sh4Offline32 elf mirai ext renesas zbetcheckin
2023-08-01 00:42:03http://94.156.161.21/AB4g5/Josho.ppcOffline32 elf mirai ext PowerPC zbetcheckin
2023-08-01 00:42:03http://94.156.161.21/AB4g5/Josho.arm5Offline32 arm elf mirai ext zbetcheckin
2023-08-01 00:41:03http://94.156.161.21/AB4g5/Josho.m68kOffline32 elf mirai ext motorola zbetcheckin
2023-08-01 00:23:04http://94.156.161.21/AB4g5/Josho.x86Offline 32-bit elf mirai ext x86-32 geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-08-03 21:42:04b9cca900a65652b103da43de678c67c11a0e8f894117bb46482b3bf3a79d7e05elfMirai
2023-08-03 21:41:05f727a2d45fe1481f5c18411c90997de17405654af26ac0a76f84de77dc977926elfMirai
2023-08-03 21:41:05ccb60cafe662ec89fe97506adb5b33ec86f3c5a5eb707c5550fe0c9060b19cd9elfMirai
2023-08-03 21:36:045babcc16179fec33d53f2b54b8f481ed70fe7dc46385a69f7566a75418cb5edcelfMirai
2023-08-03 21:36:04bf720a851ab1eb5bb7c3d025b21c5d740341f53cd24f8439306453a19c934c86elfMirai
2023-08-03 21:36:0448a5629e9e32ce54a6dd666838f314c8891794912b0e9fc5103d7011ff29b8c1elfMirai
2023-08-03 20:56:048cad93dac4260d4294bd45146ed1935c78542734a03e76b80265dfb2cf542a68elfMirai
2023-08-03 04:23:048d65b1c26285a08ee8cb11aa868984bd37553e2d2a8e5171d2460c32ca89a2e6elfMirai
2023-08-03 04:23:039db1a5e089a0b16b3b9a584cb3e5e55eb68620d0ab6b229cf24d49f32b9391beelfMirai
2023-08-03 04:22:05b14eb9596f91c1625c3df29413fa08ba313a6b9e6d7fb1297fba74761c135568elfMirai
2023-08-03 04:22:0560372d900506da46bf83e318f5f8f8c3219dcda3fca977f0172367d6825dfcdbelfGafgyt
2023-08-03 04:22:058347e8933783cd4129240b96ae5e665cedc5848ce1cbb7d9f58eb97aaa29b108elfMirai
2023-08-03 04:22:05881e7126f65751a41d59e846908246030f834ec03b15c1ef2cae8c4a1098cf15elfMirai
2023-08-03 04:21:061ef241ca77d2de374113db8b9e9bad4133142326683f2c7954bbab6415780dffelfMirai
2023-08-03 04:21:06ec83fcc94d1fd981d13c7e5f3318671f3c96e677eaa956c7c1df4de2444c326felfMirai
2023-08-03 04:21:0694797cd702cf50fea6d780ab0d94cb2a0aa8ee9aa5332e71479adaa7a5245f27elfMirai
2023-08-03 04:21:068ef658a73b292410dd6a570bc65a0f398e838b5adb141eb9dc81ad124fb46f80elfMirai
2023-08-03 04:21:06a908289bef30086660453ab8809af758af3d445ecda4010211282eb067fef3abelfMirai
2023-08-03 04:16:05aa2184f3af0af080ef946b5e0b4aa85c1ce412fa4979e026d88832678427aed0sh  
2023-08-01 21:28:04f0eb89b91e787324bb6f4a082fccea951b00f32ae62f31c80d9d83f4c53a0a65elfMirai
2023-08-01 02:40:0746ff9f7c0e437df7dd6e1c69790c8fc94e65091e9f3cf1f3243c808f1a1e8621elfGafgyt
2023-08-01 01:30:09a3944cf1b59a8481386873d6fa131c9e7fbb85ae0b0642d65d0962f94a2e3dbeelfMirai
2023-08-01 01:30:09b435277ac428d968821c44d98673d6b04e73ca054723d2f09f42f2245777bec3elfMirai
2023-08-01 00:42:047722969303bcc72aade0f9688089b9f24f7abac2a47dc9170abde533fa745ffbelfMirai
2023-08-01 00:42:04f0f911e5023140e3b401540d9b91c66f56ae21923255d145779c88405e88f02felfMirai
2023-08-01 00:42:0419b6e4ca25940457310af99a3498c6043adb0ccece6d3300ad828f746dc095b9elfMirai
2023-08-01 00:42:034d6d22aea7a1147911f99a57718a41b144b0c70761198629cb5d13d0b86c359felfMirai
2023-08-01 00:42:0383b023c87016de3b7e4633773cfc1c034f8923da968850c998bef0660431df70elfMirai
2023-08-01 00:42:032aad2a03c18e8f87f0669a8083c5ac2a96e15a48cc2f2d6ee762898b15f48e69elfMirai
2023-08-01 00:41:03db72c6b7f6598485b9fb3e1121d380c7d12fd154f3b9143082058c2b1d9a5a86elfMirai
2023-08-01 00:23:039132dce93a1db68341cd4d7cf79411cdeae2cf2a1a3f64a805f9ec50de680fe8elfMirai