URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 99.71.130.109
Firstseen:2024-05-20 21:19:04 UTC
Total malware sites :48
Online malware sites :29 (60%)
Offline Malware sites :19 (40%)
Newest active malware site :2024-05-24 04:30:53 UTC
Oldest active malware site :2024-05-20 21:19:20 UTC (Age: 2 years, 0 months, 17 days, 16 hours, 9 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-05-20 21:19:20 99.71.130.10999-71-130-109.lightspeed.lsanca.sbcglobal.netNot listedAS7018 ATT-INTERNET4- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-05-24 04:30:53http://99.71.130.109:8021//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:30:52http://99.71.130.109:8041//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:30:22http://99.71.130.109:8050//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:30:01http://99.71.130.109:8034//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:29:55http://99.71.130.109:8055//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:29:47http://99.71.130.109:8039//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:29:44http://99.71.130.109:8042//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:29:30http://99.71.130.109:8040//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:29:13http://99.71.130.109:8028//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:29:09http://99.71.130.109:8048//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:28:58http://99.71.130.109:8027//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:28:57http://99.71.130.109:8049//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:28:57http://99.71.130.109:8054//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:28:57http://99.71.130.109:8035//sshdOnlinebackdoor sshdkit abus3reports
2024-05-24 04:28:40http://99.71.130.109:8025//sshdOfflinebackdoor sshdkit abus3reports
2024-05-24 04:28:39http://99.71.130.109:8022//sshdOnlinebackdoor sshdkit abus3reports
2024-05-23 19:29:14http://99.71.130.109:8042/sshOfflineelf RacWatchin8872
2024-05-23 19:29:13http://99.71.130.109:8041/sshOfflineelf RacWatchin8872
2024-05-23 19:29:12http://99.71.130.109:8035/sshOfflineelf RacWatchin8872
2024-05-23 19:29:11http://99.71.130.109:8048/sshOfflineelf RacWatchin8872
2024-05-23 19:29:11http://99.71.130.109:8049/sshOfflineelf RacWatchin8872
2024-05-23 19:29:10http://99.71.130.109:8050/sshOfflineelf RacWatchin8872
2024-05-23 19:29:10http://99.71.130.109:8027/sshOfflineelf RacWatchin8872
2024-05-23 19:29:10http://99.71.130.109:8039/sshOfflineelf RacWatchin8872
2024-05-23 19:29:08http://99.71.130.109:8028/sshOfflineelf RacWatchin8872
2024-05-23 19:29:08http://99.71.130.109:8055/sshOfflineelf RacWatchin8872
2024-05-23 19:29:07http://99.71.130.109:8022/sshOfflineelf RacWatchin8872
2024-05-23 19:29:07http://99.71.130.109:8040/sshOfflineelf RacWatchin8872
2024-05-23 19:29:05http://99.71.130.109:8025/sshOfflineelf RacWatchin8872
2024-05-23 19:29:05http://99.71.130.109:8054/sshOfflineelf RacWatchin8872
2024-05-23 19:29:05http://99.71.130.109:8034/sshOfflineelf RacWatchin8872
2024-05-23 19:29:05http://99.71.130.109:8021/sshOfflineelf RacWatchin8872
2024-05-20 21:22:06http://99.71.130.109:8049/sshdOnlineelf abus3reports
2024-05-20 21:22:04http://99.71.130.109:8054/sshdOnlineelf abus3reports
2024-05-20 21:22:01http://99.71.130.109:8040/sshdOnlineelf abus3reports
2024-05-20 21:21:59http://99.71.130.109:8050/sshdOnlineelf abus3reports
2024-05-20 21:21:51http://99.71.130.109:8041/sshdOnlineelf abus3reports
2024-05-20 21:21:49http://99.71.130.109:8048/sshdOnlineelf abus3reports
2024-05-20 21:21:43http://99.71.130.109:8035/sshdOnlineelf abus3reports
2024-05-20 21:21:22http://99.71.130.109:8027/sshdOnlineelf abus3reports
2024-05-20 21:21:17http://99.71.130.109:8025/sshdOfflineelf abus3reports
2024-05-20 21:21:03http://99.71.130.109:8028/sshdOnlineelf abus3reports
2024-05-20 21:19:55http://99.71.130.109:8042/sshdOnlineelf abus3reports
2024-05-20 21:19:54http://99.71.130.109:8022/sshdOnlineelf abus3reports
2024-05-20 21:19:44http://99.71.130.109:8034/sshdOfflineelf abus3reports
2024-05-20 21:19:35http://99.71.130.109:8021/sshdOnlineelf abus3reports
2024-05-20 21:19:28http://99.71.130.109:8039/sshdOnlineelf abus3reports
2024-05-20 21:19:20http://99.71.130.109:8055/sshdOnlineelf abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-09-10 02:12:275e38ff37058bd1bc90c33556b5c3900b8b93947f07d972c01cf6bf8ef6d69637elf  
2024-07-03 12:02:301147798308afcb78323ec7c61a3680aaa349bfa68c66f9daa4dcac4126fad10felf  
2024-07-02 00:55:575ac5a02d93cda9b7515abb6e428f9d643fca07806d0efeba5f05cd84c5f5181eelf  
2024-05-24 04:30:53ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:30:52ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:30:21ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:30:00ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:29:55ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:29:46ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:29:44ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:29:30ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:29:13ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:29:07ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:28:58ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:28:57ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:28:57ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:28:57ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:28:39ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-24 04:28:39ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:22:05ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:22:03ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:22:01ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:21:58ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:21:50ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:21:49ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:21:42ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:21:22ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:21:16ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:21:02ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:19:55ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:19:54ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:19:43ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:19:35ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:19:28ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf  
2024-05-20 21:19:17ab69ef32017a5365ee0e7faca03e1352382865c5672e989d99d2d77ec91c33efelf