URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: cdn.valgap.org
Domain registrar:Spaceship -
Domain registration date:2025-06-01 06:03:21 UTC
Abuse complaint sent?: Yes (2025-07-10 13:17:01 UTC to ops{at}pir[dot]org)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-07-10 13:16:04 UTC
Total malware sites :24
Online malware sites :0 (0%)
Offline Malware sites :24 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-07-10 13:16:11 206.123.128.90SBL692931AS207083 HostSlim-Global-Network- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-07-10 13:32:08http://cdn.valgap.org/bot.mipsOfflinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:32:07http://cdn.valgap.org/bot.m68kOfflinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:32:07http://cdn.valgap.org/awsOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:32:06http://cdn.valgap.org/goaheadOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:15http://cdn.valgap.org/zteOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:15http://cdn.valgap.org/jawsOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:15http://cdn.valgap.org/thinkphpOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:12http://cdn.valgap.org/bot.x86Offlinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:12http://cdn.valgap.org/pulseOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/huaweiOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/realtekOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/hnapOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.ppcOfflinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.sh4Offlinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/zyxelOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.x86_64Offlinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.arm6Offlinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.armOfflinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.mpslOfflinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/yarnOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.arm5Offlinebotnetdomain elf mirai ext ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/lgOfflinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/gpon443Offlinebotnetdomain sh ua-wget NDA0E
2025-07-10 13:16:11http://cdn.valgap.org/bot.arm7Offlinebotnetdomain elf mirai ext ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-07-10 13:32:089b2fcb661af85d6d1901dc0056c1cf49d32eeb4efda9506e1d1615876c83ce87elfMirai
2025-07-10 13:32:07ee49dcd1f6d3d5c292dd57dc274a223a361264e91aa750797e68453e77c05eccelfMirai
2025-07-10 13:32:0718ebc3f3e74fc7a11f097eefd4f5864a7a49b490449dc6adf37fbe86ba279427sh 
2025-07-10 13:32:06a700a9bfb68fe0eaae7b36b7961dd597fc898a97309a5ad5737d11d804cee7a0sh 
2025-07-10 13:16:13480c03f412f16c82a15f30067194e43269addb1c90d47fb7315e5a4ecfe7fdedsh 
2025-07-10 13:16:131532042b11c1469ea5b9e421f85a9e0f046e1c3eeae9d002b9a566c7d980a4a0sh 
2025-07-10 13:16:136766a194886b144ae198b70dc1164abf781ae54309d44e76dd1f9feb5432e959sh 
2025-07-10 13:16:1192ffa4a78aa9744345f724b2ef49f3048c20982b73dbcf26db73fa7c9bc5df27sh 
2025-07-10 13:16:11d2efd7b961eb1ac10a33fd751de316b14c4b10c06a812bd0ff85951cede44ea8elfMirai
2025-07-10 13:16:113416131cbc8e604d87c962b7fb99c1ecdd075abf401a28e20711e13748de1cbcsh 
2025-07-10 13:16:11559443514ed9e0b82a9eedf29a5db12bf6d8b20373e652cf9142e0c5bf8c9b11sh 
2025-07-10 13:16:119df0bda4ef5533e944532c45f8cdeb1dc0a8fba92c668eab3978f487cbb41974sh 
2025-07-10 13:16:1153517483514037c81aaa3feef8cf2d47b4848272b76479a880ebd36072bd8996elfMirai
2025-07-10 13:16:11a022268a251c1cfc9309f823235ce273e0368e620dce42e341f5e78357f83d1belfMirai
2025-07-10 13:16:1166b59213ba9d602854fbd06c1c880ffc51a55c0f364998b8818035ac71a43d15sh 
2025-07-10 13:16:1124379b0bf7c98c369a824afb0a003343ca5dc0a859d2c0bb6e7fec0b8d5f4eaaelfMirai
2025-07-10 13:16:11adbb51bf30cf198891fa8a30aa39ca0f89432e0975c3977598211b070a00e5bbelfMirai
2025-07-10 13:16:110853f1d18d6da72e410b95c0e1beecf345592e49bda89e3c5d4bbdbdad3599b8elfMirai
2025-07-10 13:16:11d28c5e4dad0e2af3e58a5b65bd2aa4a9a438f45681eab0aa8f122d1f8273a598elfMirai
2025-07-10 13:16:111c339842b9730fa557f03b8cf4dcc2277f31011bef16db8d9b3503f8c0ca0ffbsh 
2025-07-10 13:16:11917d144ce8a39273a078d7fe8166125e81a66e7ac81a162bf6f1389c0e213e82elfMirai
2025-07-10 13:16:11c6dfa181522dc9acd75b87c34a2e522122dc541043993e32d9a7c496ebac1bfcsh 
2025-07-10 13:16:11b5a94259016263d3b72b80dbbbdf5f2df0d358c53d34b01874c8efc7c66dd37bsh 
2025-07-10 13:16:11e6f93ea500870da11fadc88d02c48d62e62449f532bdcee007b47eee5db51b76elfMirai