URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: libs.9tb.org
Domain registrar:Gname -
Domain registration date:2025-11-02 16:58:40 UTC
Abuse complaint sent?: Yes (2026-03-19 21:10:02 UTC to ops{at}pir[dot]org)
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-03-19 21:09:05 UTC
Total malware sites :15
Online malware sites :0 (0%)
Offline Malware sites :15 (100%)
A record(s) observed :4

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-22 14:39:55 144.31.4.224s210715.love-is.nexusNot listedAS215730 H2NEXUS-AS- PLno
2026-03-21 08:25:13 142.248.148.126Not listedAS49304 SAKURA-AS- JPno
2026-03-21 02:33:31 142.248.149.134Not listedAS49304 SAKURA-AS- JPno
2026-03-19 21:09:21 139.162.114.163139-162-114-163.ip.linodeusercontent.comNot listedAS63949 AKAMAI-LINODE-AP- JPno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-19 21:25:24http://libs.9tb.org/linux_386Offlineelf mirai ext ua-wget x86 botnetkiller
2026-03-19 21:25:24http://libs.9tb.org/linux_arm7Offlinearm elf gafgyt ext mirai ext ua-wget botnetkiller
2026-03-19 21:25:24http://libs.9tb.org/linux_amd64Offlineelf mirai ext ua-wget x86 botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_ppc64elOfflineelf mirai ext PowerPC ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_aarch64Offlinearm elf mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_mips_hardfloatOfflineelf mips mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_mipsel_softfloatOfflineelf mips mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_mipsel_hardfloatOfflineelf mips mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_arm6Offlinearm elf gafgyt ext mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_arm5Offlinearm elf gafgyt ext mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_mips64Offlineelf mips mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_mips64elOfflineelf mips mirai ext ua-wget botnetkiller
2026-03-19 21:09:27http://libs.9tb.org/linux_ppc64Offlineelf mirai ext PowerPC ua-wget botnetkiller
2026-03-19 21:09:22http://libs.9tb.org/linux_mips_softfloatOfflineelf mips mirai ext ua-wget botnetkiller
2026-03-19 21:09:21http://libs.9tb.org/dddd.shOfflinemirai ext sh ua-wget botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-20 07:49:05a61c74d12b3e33d976eac340cb3039a7ef455b7bc362f4b956083e45de566a2celf 
2026-03-20 07:36:55d58724360b47456e9f5162b1ff011a2ae8b797be15a37ed80d01d96fb7faac5felfGafgyt
2026-03-20 07:25:4087bcfcd7e978dc58619b9ec918d47cc6ef8af704baa89fcd9eb0d3e49db86305elf 
2026-03-20 07:22:03dcf5df996a112e892bae324b5e3c0664ad4d4f9f473494bcaad1cac3adedb512elf 
2026-03-20 07:14:06471ad160762a5c3f541d4e76ee086ee351da2e280daf11d6d009f89366395d83elfGafgyt
2026-03-20 07:01:44ad70845892f5115877371e98bfb51492add9182a6cf4cf5f8001138af5b509daelfGafgyt
2026-03-20 06:50:464a665feddc2f1e4ed7665f49c2dfae1d05b11d6fe921e2e4f7ae1798fee0c89aelf 
2026-03-20 06:48:494ddefa7635a60e03ff39678587427cc09f810a65b1c33e1d065174fbf98042efelf 
2026-03-20 06:44:23c69e69dc3ae7633b9476072001c4eaaeb8dd8c85700b97484dfdda3d86fe6fecelf 
2026-03-20 06:42:5119d22973789738ba9081ebaee823230512489ecfc680d51144cb3d9bcd4cc833elf 
2026-03-20 06:37:258a18e3f3a41b64fa23d231fdc33a941b7b5f5252374c6180a3c63b4f6a99d68delf 
2026-03-20 06:35:149ddb3ce1d5a6b94de8e55c093b20ff289872814d4d2f849407e08e87b6159650elf 
2026-03-19 21:25:240090764bcf2db6ec2c2dfac1726190d219b05174727f330c998452cef71edab2elfGafgyt
2026-03-19 21:25:24c8f3b84814fe469e2d551c141b37bf74e350bfeafb31a530d2582788cc445789elf 
2026-03-19 21:25:2448bb77a7a55300ad0acdac1e8d80f3afd68e143cd5bb6512c7e6f71a554544bfelf 
2026-03-19 21:09:278c2ebd1990cb95e7ded08c14cf1a273921fb14a941f280f60e8fbcea4a9961e4elf 
2026-03-19 21:09:27693804fcbbb4d97efbeb03d2b30f858de871460f58cfbb90e36d9042a20953edelf 
2026-03-19 21:09:27b1599da80f790e8ec4057e2f8794c81a1b03cba12efe57f754e62626ef6b74eaelf 
2026-03-19 21:09:27b7a92042924957d6e8a5afa3948abf767cb7b304f73445f0ff0d6001a68527c4elf 
2026-03-19 21:09:277b45e5dc85e06ce7d05fef0596066df3a584200b25d9808051253152e886a963elf 
2026-03-19 21:09:27ea67345e99150d5d38382dcad1e508784a28ea8347440191d0c698a57c4b2cffelf 
2026-03-19 21:09:261d820e6c99e11b266ca47a7e465dd965a282805b3d60179f5c08101e395457e3elf 
2026-03-19 21:09:26d14f2cbe763c083e82375e4b6fa19386d8514e1b35a87e6d5e42d465a48e818celf 
2026-03-19 21:09:26bd6f00168e9e92434533fc1cbe5933c22bdde8239e7d6b7bf7e26b761723e0c0elf 
2026-03-19 21:09:267c00939422d1e1c2c1720e3322ca50ca660de227730b48694d28b841a572f1f5elf 
2026-03-19 21:09:22baa2f8273b8052d53401e12d1d22640c0b3a44c3cb1e396baa95bcdd8322eedaelf 
2026-03-19 21:09:210e7af68125450f1a0071d23518fa90f4c9f7d6342d7edd077cc4888e8da1ca2csh