URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: libss.0x504.com
Domain registrar:NICENIC -
Domain registration date:2025-04-23 09:00:23 UTC
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-03-22 15:41:05 UTC
Total malware sites :16
Online malware sites :16 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-03-28 13:42:17 UTC
Oldest active malware site :2026-03-22 15:41:20 UTC (Age: 6 days, 8 hours, 17 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-22 15:41:19 144.31.4.224s210715.love-is.nexusNot listedAS215730 H2NEXUS-AS- PLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-03-28 13:42:17http://libss.0x504.com/xlh/cccc.shOnlinesh ua-wget botnetkiller
2026-03-22 15:44:22http://libss.0x504.com/linux_mips64elOnlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:22http://libss.0x504.com/linux_arm6Onlinebotnetdomain elf gafgyt ext ua-wget NDA0E
2026-03-22 15:44:22http://libss.0x504.com/linux_ppc64Onlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:22http://libss.0x504.com/linux_ppc64elOnlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:22http://libss.0x504.com/linux_arm5Onlinebotnetdomain elf gafgyt ext ua-wget NDA0E
2026-03-22 15:44:22http://libss.0x504.com/linux_mips_softfloatOnlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:21http://libss.0x504.com/linux_mips64Onlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:20http://libss.0x504.com/linux_aarch64Onlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:20http://libss.0x504.com/linux_amd64Onlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:19http://libss.0x504.com/linux_mipsel_softfloatOnlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:19http://libss.0x504.com/linux_386Onlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:19http://libss.0x504.com/linux_mipsel_hardfloatOnlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:19http://libss.0x504.com/linux_mips_hardfloatOnlinebotnetdomain elf ua-wget NDA0E
2026-03-22 15:44:17http://libss.0x504.com/linux_arm7Onlinebotnetdomain elf gafgyt ext ua-wget NDA0E
2026-03-22 15:41:20http://libss.0x504.com/cccc.shOnlinebotnetdomain sh ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-03-28 22:34:526211f5146d6911a4e50ccef8a9ace273dcc71d1bf6861ac89dfb8a45e21db870elf 
2026-03-28 22:31:4380b6e950105fd600077421de8415319441813e24748bb9f5c60e36fe6ea6b490elf 
2026-03-28 22:29:2432ae6596f0b865eb056b1feae5b41cebf3e1b9f7809d9d9980ee16a0b2a88958elf 
2026-03-28 22:26:5588775d9733d62cb2c16aeaee6862fc8af44c8b5afa389c6d91f14c6b90256981elf 
2026-03-28 22:14:455cf06e1b31733c256a72dce55a4ff2050aa9d08b080f70198a87cb2e7bdf7f28elf 
2026-03-28 22:06:5033ee5f8de63b859ac28649988a4515665eb48025fafc28541ec51951f7f6a84belf 
2026-03-28 22:00:109a8267ee382a67b7f05fce31664d3774e8ff827b37eff2974111975e37d7ba24elf 
2026-03-28 21:57:34a079445d02a2f67598feac46a8def3985c2306bfc015d41810178523218caaa6elf 
2026-03-28 21:27:559ef44beeee7c19cafa67ffeb622f1d636c040cdf0e1a4f53f4423046aaf502eaelf 
2026-03-28 21:18:4400bd9a8763aed0cb7b33f1156a7cc5db12305b5e29988e250bb8190fe6d9f588elf 
2026-03-28 21:17:122fd9a191840dd738087420df2e4008776ab672de6f2f459d1a63681c91229d7celf 
2026-03-28 21:13:3054bb89310955e2f6a0edd88b820af7c82dc8ca1da359c0a6c41001ff0c685da5elf 
2026-03-28 21:10:062544251fb0dfa1eaca402526eeecc52c583b2586e2af6b912dd5c198c1b871c0elf 
2026-03-28 21:02:535a132624a5b57a97629678aa95d4475e587ea154c17c0f35708b12eba030c367elf 
2026-03-28 13:42:1767e1ae614f21cbfe2352d02dd5fc41245bbf4441440c6ee14de40807e185b203sh 
2026-03-22 15:44:22d58724360b47456e9f5162b1ff011a2ae8b797be15a37ed80d01d96fb7faac5felfGafgyt
2026-03-22 15:44:229ddb3ce1d5a6b94de8e55c093b20ff289872814d4d2f849407e08e87b6159650elf 
2026-03-22 15:44:2287bcfcd7e978dc58619b9ec918d47cc6ef8af704baa89fcd9eb0d3e49db86305elf 
2026-03-22 15:44:228a18e3f3a41b64fa23d231fdc33a941b7b5f5252374c6180a3c63b4f6a99d68delf 
2026-03-22 15:44:22ad70845892f5115877371e98bfb51492add9182a6cf4cf5f8001138af5b509daelfGafgyt
2026-03-22 15:44:21b7a92042924957d6e8a5afa3948abf767cb7b304f73445f0ff0d6001a68527c4elf 
2026-03-22 15:44:21b1599da80f790e8ec4057e2f8794c81a1b03cba12efe57f754e62626ef6b74eaelf 
2026-03-22 15:44:20dcf5df996a112e892bae324b5e3c0664ad4d4f9f473494bcaad1cac3adedb512elf 
2026-03-22 15:44:19a61c74d12b3e33d976eac340cb3039a7ef455b7bc362f4b956083e45de566a2celf 
2026-03-22 15:44:1919d22973789738ba9081ebaee823230512489ecfc680d51144cb3d9bcd4cc833elf 
2026-03-22 15:44:19c69e69dc3ae7633b9476072001c4eaaeb8dd8c85700b97484dfdda3d86fe6fecelf 
2026-03-22 15:44:194ddefa7635a60e03ff39678587427cc09f810a65b1c33e1d065174fbf98042efelf 
2026-03-22 15:44:194a665feddc2f1e4ed7665f49c2dfae1d05b11d6fe921e2e4f7ae1798fee0c89aelf 
2026-03-22 15:44:17471ad160762a5c3f541d4e76ee086ee351da2e280daf11d6d009f89366395d83elfGafgyt
2026-03-22 15:41:1914599c8078954c4255076b866a6e0c302bf9e643875a77e1c4d315f3905d65bcsh