URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 94.249.228.212
Firstseen:2026-03-26 08:19:05 UTC
Total malware sites :16
Online malware sites :16 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-03-27 11:24:18 UTC
Oldest active malware site :2026-03-26 08:19:25 UTC (Age: 1 day, 6 hours, 9 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-26 08:19:25 94.249.228.212placeholder.noez.deNot listedAS214929 LastResponse- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-27 11:24:18http://94.249.228.212/iran.mipsrouterOnlineelf mirai ext ua-wget BlinkzSec
2026-03-27 11:23:14http://94.249.228.212/cat.shOnlinemirai ext sh ua-wget BlinkzSec
2026-03-27 08:56:06http://94.249.228.212/iran.x86_64Onlinemirai ext ua-wget abuse_ch
2026-03-27 08:56:06http://94.249.228.212/iran.m68kOnlinemirai ext ua-wget abuse_ch
2026-03-27 08:56:06http://94.249.228.212/iran.aarch64Onlinemirai ext ua-wget abuse_ch
2026-03-27 08:56:06http://94.249.228.212/iran.mipsOnlinemirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.armv6lOnlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.mipselOnlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.i486Onlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.sparcOnlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.arcOnlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.powerpcOnlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.armv7lOnlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.armv4lOnlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.sh4Onlineelf mirai ext ua-wget abuse_ch
2026-03-26 08:19:25http://94.249.228.212/iran.armv5lOnlineelf mirai ext ua-wget abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-27 11:24:18f8274b271e54f32ee52baff234db0800dfaec945ad5937807d9d893885d75dadelfMirai
2026-03-27 11:23:1405b42d715d54d8323e5880d2e8081ad1fbe2a1ecbdb6f125cfcca011a042079eshMirai
2026-03-27 08:56:06e8401e2e92d1d7ce3943ab8572aa50874bae6e832bb0ad7f27b705d5bcb7bd97elfMirai
2026-03-27 08:56:062e14916bcf05bdeda03f9aa28a2efe44152cfa2b42cc12eeae66e83a45e4d433elfMirai
2026-03-27 08:56:0683de4269221aeb74db1618e7903a9547fec587af08f07e178fc76c55e513c142elfMirai
2026-03-27 08:56:06514e1203a70dc1d2c336b635ea4eee7844fe62ee6543c8128fa5419abd050787elfMirai
2026-03-26 08:19:240a05916360192b441abe9eb1aa42f3b12c963d22a92893aa62a07afce26dbc27elfMirai
2026-03-26 08:19:24b59627803c1e36b3dce1b27831f01e70ad9c0a754dd02200ec58f9c271574430elfMirai
2026-03-26 08:19:24501a02eba46a0e103b38964a2e6a9bc1b0a8f53824544f84e8a12b41d562c313elfMirai
2026-03-26 08:19:24d739cf94dce3ff153cc22a4b8af4c4fe4fc82cb3ca132f23faa77c9beffa7306elfMirai
2026-03-26 08:19:2462ea0dff63ad36645cff88b905c3fb0096c92db4bf571ddc312b20142cc0c03felfMirai
2026-03-26 08:19:24efa1a2bfb85f8d16c46e879bad1c786c26df58377f346bba92b515e07abf4189elfMirai
2026-03-26 08:19:248d13aea9c3759414f1888998dd75f3f52d027587cf010f9570adccce8b96301belfMirai
2026-03-26 08:19:2442258aad7bdd5e063523159905dbf35a87b4a9e13a091d9d9e17f030dfe9af6aelfMirai
2026-03-26 08:19:24dfd4e8bf4ee5b630791cd1f0bbfffdd2146bde0c28fdd241fc818b7fbc1e9e8aelfMirai
2026-03-26 08:19:2498bc000407544dd8e14d30a3c90ae5422076bdcbd0afb6976729a2c4ccb3c54belfMirai