URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: banthis.su
Domain registrar:R01 -
Domain registration date:2024-12-08 06:22:19 UTC
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2024-12-16 14:18:04 UTC
Total malware sites :23
Online malware sites :0 (0%)
Offline Malware sites :23 (100%)
A record(s) observed :11

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-03-16 09:06:57 185.196.9.228noballs.lolSBL640645AS42624 swissnetwork02- GBno
2025-03-15 16:09:55 164.90.197.54Not listedAS14061 DIGITALOCEAN-ASN- NLno
2025-03-14 16:54:07 146.190.24.176Not listedAS14061 DIGITALOCEAN-ASN- NLno
2025-03-12 23:19:36 178.128.235.246Not listedAS14061 DIGITALOCEAN-ASN- CAno
2025-03-10 20:10:48 24.199.121.112Not listedAS14061 DIGITALOCEAN-ASN- USno
2025-03-01 21:42:06 193.143.1.117SBL634458AS198953 proton66- RUno
2025-02-28 21:25:21 185.157.247.126ip.126-247-157-185.reverse.inovaperf.frNot listedAS34534 BULLIONET- FRno
2025-02-15 13:43:27 185.142.53.41rootNot listedAS34534 BULLIONET- FRno
2024-12-16 14:18:06 185.142.53.6ip.6-53-142-185.reverse.cpuserv.frNot listedAS34534 BULLIONET- FRno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-02-20 14:42:03http://banthis.su/dlr.ppcOfflinebotnetdomain elf fbi.gov NDA0E
2025-02-20 14:42:03http://banthis.su/dlr.x86Offlinebotnetdomain elf fbi.gov NDA0E
2025-02-20 14:42:03http://banthis.su/dlr.spcOfflinebotnetdomain elf fbi.gov NDA0E
2025-02-20 14:42:03http://banthis.su/dlr.m68kOfflinebotnetdomain elf fbi.gov NDA0E
2024-12-16 14:20:10http://banthis.su/wget.shOffline404 botnetdomain mirai ext sh ua-wget NDA0E
2024-12-16 14:20:08http://banthis.su/curl.shOffline404 botnetdomain mirai ext sh ua-wget NDA0E
2024-12-16 14:20:07http://banthis.su/tarm6Offline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:19:07http://banthis.su/dlr.mpslOffline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:19:06http://banthis.su/skid.mipsOffline404 botnetdomain elf ua-wget NDA0E
2024-12-16 14:19:06http://banthis.su/dlr.armOffline404 botnetdomain elf ua-wget NDA0E
2024-12-16 14:19:06http://banthis.su/darm7Offline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:19:06http://banthis.su/hmipsOffline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:19:05http://banthis.su/dlr.arm7Offline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:19:05http://banthis.su/dlr.arm5Offline404 botnetdomain elf ua-wget NDA0E
2024-12-16 14:19:05http://banthis.su/dlr.mipsOffline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:19:05http://banthis.su/dlr.sh4Offline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:18:06http://banthis.su/tarm7Offline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:18:06http://banthis.su/tarm5Offline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:18:06http://banthis.su/tsh4Offline404 botnetdomain elf gafgyt ext ua-wget NDA0E
2024-12-16 14:18:06http://banthis.su/tarmOffline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:18:06http://banthis.su/tmipsOffline404 botnetdomain elf mirai ext ua-wget NDA0E
2024-12-16 14:18:06http://banthis.su/tmpslOffline404 botnetdomain elf mirai ext ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-03-01 17:35:03da80863061dc0e02682bb76dcb69b6012e205d7c55252ec228416cdc813bc81eshMirai
2025-03-01 16:29:591ad5621421e5f0d4c673d5ee8948f678cf992735d7c84c25bd7b8f2c0012479cshMirai
2025-02-28 22:06:130343cd4da3214cb98df604d40e5422b4e4d93197ffca7aca74da98cc56902ae2elfMirai
2025-02-28 22:02:58ee5f0f6724abdf85f8814fb515d2b427aba0a9a2a3a71ae3c684625c64a98de7elfMirai
2025-02-28 22:01:326918e5351924a5df8a94a50afc2e634977d30cbd1c7c0123e3bb72c85d11fab6shMirai
2025-02-28 21:58:2104f153396823c359abb972cba4487f57d58f09c7788e30834307945550302090elfMirai
2025-02-28 21:57:072f1509f448a25d6a9f87ea194487b0f36c9ef71c255f35bba58d51c8ec4ff85felfMirai
2025-02-28 21:51:567c485e0a785c06f12dc7bae2f2f77f30e040300125b4fc7a0c69da4c12a9f7d5shMirai
2025-02-28 21:28:57b835ea1518783cd906bc0c3c978c948bce83027fec4db4c482cd84c2374d01c7elfMirai
2025-02-28 21:28:3001401c31c9768b24329e94d1961fb9933d8e1ed4642148e012210bd22706b3d9elfMirai
2025-02-28 21:25:21796b727c2e1e3159fe182b10917159d73578378cf2c156cb5fa2c85de459f00delfGafgyt
2025-02-20 05:43:2857b0aa9d927b0c400e59bbafcbbc71174e13933d0943f3b69caa0bcca78db307elfMirai
2025-02-20 05:06:0201f02c63d1668e5cc0946d9aaba4dffb35a5c4e4f1fa3f7d745746e52892ab3delfMirai
2025-02-20 05:03:2879076da109a2b9fbd073e16c09228a32be81a133455576bd58f641670de5a433elfMirai
2025-02-20 00:05:1020bfe7da0be460dbb7363a7ceb7ab70fafa11810b7362aaf6635ca8643863fb7elfMirai
2025-02-20 00:02:30badddd90fcc121fc2d43b511e876db9048587a9574664832c7fdaa2dd595dcc8elfMirai
2025-02-20 00:00:48564c243b1f553f14bc3b7bb40299a554e40d02eaedd7c7f17da7259221685fb7elfGafgyt
2025-02-16 05:37:1947f2b64af6b8bb6d7db40ae5febeff478515043ffce1bd304c258683f9d9282cshMirai
2025-02-16 04:44:15318d9f2a75cd221b43b96d2fe1c8ef0f09f295e2d6293e78d36bf086d0d47c70elfMirai
2025-02-16 03:51:300f0307270a78c8ed0d813a6dd50bedbe281da11f52e78d1e8f5678d929d486b3elfMirai
2025-02-16 03:02:307185b11e03083282e3808d50e8a2ab13d3a1d3dbf722334367390be28ea60180shMirai
2025-02-15 16:30:254306df94e4c1acd24418adbd57af1ad2351fc4cb2c5bc7eed349492f601fcab8elf 
2025-02-15 15:27:389352636497437c219220be662e40369e03810706a32b8c60de2dc255413fd170elf 
2025-02-15 15:08:239de1932d94508eb8811d308230ba93d38f04723c903e8cfadce2da52c3dd3768elfMirai
2025-02-15 14:46:04611c37e4c9627439ede21ddfb0d1897a412183280f7cd50218b9a61c9287f2dbelfMirai
2024-12-16 14:20:10b6a6cd4a15be361c9154510b635330d6f73c25fe022e5a4518af5a4518610c15sh  
2024-12-16 14:20:085517b11aee1c8ca8e268e4050083463f02bb9195b8bcd30b2f544159fe098b3esh 
2024-12-16 14:20:0769490a8947c1f25ac8fd4fc0b839aad5cc21232b5268489b6f317a9121439043elfMirai
2024-12-16 14:19:068af6520884b12350097cea5e452e0515d5ad83d23d0e4623266afa1f2c0c85cbelfMirai
2024-12-16 14:19:06488eea9fa3708c18ed0aab7132a7afe4b28fc64b46db60f6211c5c003b52c6ffelf  
2024-12-16 14:19:068f0f687db309bcae6e8ac78502fc00edac03260c2ee0c843c295f6d2057f9053elfMirai
2024-12-16 14:18:06e6ff63d78c6c1f39f833f009c70b5a0163e7ac7b50b4d3183e4892a126544080elfGafgyt
2024-12-16 14:18:06adc306d1685d4a96def58fceb1a09e713a483f387dfba30298f64dd8f5764b2eelfMirai
2024-12-16 14:18:06c4a60bcce49da54f7d7a2d3b7a6c4838ee67f398a1e30609a735366722a9643belfMirai
2024-12-16 14:18:06a88d890b2fe3fe9ec992c214cc22c0677237850f1e31f228438c2eb4ed6b9dc0elfMirai
2024-12-16 14:18:06d82fefa7c75004dbcbbfdb49bbbf2d47d70f13ea6df326dbacd3ec7bcd52323celfMirai
2024-12-16 14:18:06b6ef2e83c58ea734af6a01070d1fd1a06cb1b72aefa4d2e7ff4305e7d72c5306elfMirai