URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 94.156.64.143
Firstseen:2024-03-03 12:25:08 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-03-03 12:25:14 94.156.64.143Not listedAS208893 sparks- GByes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-03-03 20:01:25http://94.156.64.143/linux/xmrigMinerOfflineminer xmrig abus3reports
2024-03-03 20:01:23http://94.156.64.143/linux/xmrigDaemonOfflineminer xmrig abus3reports
2024-03-03 20:01:22http://94.156.64.143/windows/xmrigMiner.exeOfflineCoinMiner miner xmrig abus3reports
2024-03-03 20:01:19http://94.156.64.143/mac/xmrigMinerOfflineminer xmrig abus3reports
2024-03-03 20:01:15http://94.156.64.143/windows/xmrigDaemon.exeOfflineminer xmrig abus3reports
2024-03-03 20:01:06http://94.156.64.143/mac/xmrigDaemonOfflineminer xmrig abus3reports
2024-03-03 12:25:16http://94.156.64.143/.ivn.mpslOfflineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:15http://94.156.64.143/.ivn.arm6Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:15http://94.156.64.143/.ivn.arm5Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:15http://94.156.64.143/.ivn.arm7Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:15http://94.156.64.143/.ivn.i586Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:15http://94.156.64.143/.ivn.sparcOfflineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:15http://94.156.64.143/.ivn.arm4Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:15http://94.156.64.143/.ivn.m68kOfflineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:14http://94.156.64.143/.ivn.mipsOfflineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:14http://94.156.64.143/.ivn.sh4Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:14http://94.156.64.143/.ivn.i686Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:14http://94.156.64.143/.ivn.x86Offlineelf gafgyt ext mirai ext abus3reports
2024-03-03 12:25:14http://94.156.64.143/.ivn.ppcOfflineelf gafgyt ext mirai ext abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-03-03 20:01:25b653d6ca76dbe51a7a9c3cbf2d8b40e3d5d1f30495ffad5519d882abf6b52c79elf  
2024-03-03 20:01:230ea2d73e47b8642b24371be112fb04e455bc8577fa17911bd17793887cedeb7eelf 
2024-03-03 20:01:229a0181ddd6f4283764610c6ad6fd52c60b791d1424fd43c5a580194ef3676822exe CoinMiner
2024-03-03 20:01:194a7d7ca85a9d2de1c675f2d7b625998279a6e5278ff927b2834426976cc6a3f2unknown  
2024-03-03 20:01:159ad04fe6ac9ee601b2e26c5ccf4d34b68e51500021bd7ef5495013812d7b20c8exe 
2024-03-03 20:01:0689d903368a488953ddf98a22160e01fbc094e891f97eded4d319d73468be9500unknown  
2024-03-03 12:25:15fa4623388e2ba283923b877335f421b2c4deb6e30f42e21bf45b5fa5f4d60630elfGafgyt
2024-03-03 12:25:157e3cd889cbec5f96f624cd4cca32ded06310b18c02f8a17234247da30cb9fe27elfGafgyt
2024-03-03 12:25:15b17074c278edf8eb86d2669bc329ecbb2cc9354fb0831ef6db60ebcf5e4c67b4elfGafgyt
2024-03-03 12:25:158cd60b607f65b9c53daee913f717a408d30caaacadc189881a5f8dc10fc29bd9elfGafgyt
2024-03-03 12:25:15af5e4587b849eecd603ebfade9ef24e821ff185011f61434bb7c6d722e89cb88elfGafgyt
2024-03-03 12:25:15c2bc677627dc1c48507e5773d83e3ad7e5e315a2d3011c07fda8fea96f626998elfGafgyt
2024-03-03 12:25:1551efc8f2b51f1f3c5083056f96a9de6338ab1fc1909e64b4b685744d0eb43a9eelfGafgyt
2024-03-03 12:25:147bf1ba4c5536f27ba7c4c317bb8003ab6f65354f1890fd24728ed2f467ee1495elfGafgyt
2024-03-03 12:25:145830d3a37398dc673afc1a84e687753b1734bd6712c860de9524135293c946dcelfGafgyt
2024-03-03 12:25:142aab0918710e87642fc932c2b444ab09f7ed1d7e6ce6ed7e81f0f38cd868504eelfGafgyt
2024-03-03 12:25:1420b0b9ea77feff421905625d121b21257c5431f49ba2b6411787c8d7984dedf8elfGafgyt
2024-03-03 12:25:143c521d6db959df9f9ebc3dea91ec2fe68e6f5dd6865ca53c1db77ce845fe86f5elfGafgyt
2024-03-03 12:25:14d63b487e303a6a68290df9add9aa447df1ffcf5556c50d409ea6a141cd3edcc0elfGafgyt