URLhaus Database
Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).
Database Entry
IP addresses
The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.
| Firstseen (UTC) | IP address | Hostname | SBL | ASN | Country | Active? |
|---|---|---|---|---|---|---|
| 2025-06-24 15:00:50 | 199.59.243.228 | Not listed | AS16509 AMAZON-02 | US | no | |
| 2025-02-08 02:11:02 | 107.189.1.200 | Not listed | AS53667 PONYNET | LU | no |
Malware URLs
The table below shows all malware URLs that are associated with this particular host.
| Dateadded (UTC) | URL | Status | Tags | Reporter |
|---|---|---|---|---|
| 2025-02-08 02:11:03 | http://bears.pet/5 | Offline | elf geofenced HRV mirai | |
| 2025-02-08 02:11:02 | http://bears.pet/7 | Offline | elf geofenced HRV mirai | |
| 2025-02-08 02:11:02 | http://bears.pet/2 | Offline | elf geofenced HRV mirai | |
| 2025-02-08 02:11:02 | http://bears.pet/2.sh | Offline | geofenced HRV mirai | |
| 2025-02-08 02:11:02 | http://bears.pet/1 | Offline | elf geofenced HRV mirai |
The table below shows recent payloads delivery by this host.
| Firstseen (UTC) | SHA256 hash | File type | Bazaar | Signature |
|---|---|---|---|---|
| 2025-02-08 04:59:05 | 117e74e6d5c74146bdc66ae7b2cc5e148104b3128c2b48de07066e327d0f0fbb | elf | Mirai | |
| 2025-02-08 04:43:22 | a0d0d513469f9f213fb7a6746b1f94f1173ef7d69c834d924bbadfe9d2a789cc | elf | Mirai | |
| 2025-02-08 03:21:09 | c072691e9f3b634cc110f1fddac7a43e4690a7fc11657e582da34f7fc29a6b0d | elf | Mirai | |
| 2025-02-08 02:14:52 | 3b1294e989efd51c9e373b06f5548ebd176910eb311bba61333f3f76ccd46751 | sh | Mirai | |
| 2025-02-08 02:14:41 | 512cfb0717d47346a1d0e6421ac04afbfeaf3982a54562059340de1c7b138c82 | elf | Mirai |
US
LU