URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: azhvgwsv.xyz
Domain registrar:GMO Internet -
Domain registration date:2025-02-18 09:27:43 UTC
Spamhaus DBL :Spammer domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-02-01 20:18:05 UTC
Total malware sites :17
Online malware sites :0 (0%)
Offline Malware sites :17 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-01 20:20:01 118.107.41.45SBL687374AS152194 CTGSERVERLIMITED-AS-AP- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-01 23:50:46http://azhvgwsv.xyz:808/linux_mips64Offlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 23:50:31http://azhvgwsv.xyz:808/linux_mipsOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 23:41:45http://azhvgwsv.xyz:808/linux_arm64Offlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 23:26:10http://azhvgwsv.xyz:808/linux_mips_softfloatOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 23:23:12http://azhvgwsv.xyz:808/linux_mips64el_softfloatOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 23:20:44http://azhvgwsv.xyz:808/linux_mips64_softfloatOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 22:59:28http://azhvgwsv.xyz:808/linux_ppc64Offlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 22:55:15http://azhvgwsv.xyz:808/linux_mipselOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 22:40:50http://azhvgwsv.xyz:808/linux_mips64elOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 22:37:38http://azhvgwsv.xyz:808/linux_386Offlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 22:26:22http://azhvgwsv.xyz:808/linux_ppc64elOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 22:02:21http://azhvgwsv.xyz:808/linux_mipsel_softfloatOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 20:32:44http://azhvgwsv.xyz:808/linux_arm7Offlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 20:27:50http://azhvgwsv.xyz:808/linux_amd64Offlinebotnetdomain Kaiji mirai ext opendir DaveLikesMalwre
2026-02-01 20:27:15http://azhvgwsv.xyz:808/linux_arm5Offlinebotnetdomain Kaiji mirai ext opendir DaveLikesMalwre
2026-02-01 20:20:37http://azhvgwsv.xyz:808/download.shOfflinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-02-01 20:20:01http://azhvgwsv.xyz:808/linux_arm6Offlinebotnetdomain Kaiji mirai ext opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-01 20:27:505a7eaef4848d9e4056001064e5754e86383380572c3f0e43910844ee5832a5b2elfKaiji
2026-02-01 20:27:15f16d88d796861fafef6b01b464b979704790207068a147da6967a902f61052f8elfKaiji
2026-02-01 20:20:016b115dc273d943e59053a41b5637756878367ec08294dcd94307669dafd8daa9elfKaiji