URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: main.oooservers.kro.kr
Domain registrar: n/a
Domain registration date:2012-06-01 00:00:00 UTC
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-05-06 13:00:05 UTC
Total malware sites :26
Online malware sites :0 (0%)
Offline Malware sites :26 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-19 10:34:22 51.38.140.84ip84.ip-51-38-140.euNot listedAS16276 OVH- FRno
2025-05-06 13:00:19 91.208.206.217Not listedAS200019 AlexHost- MDno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-05-06 13:00:26http://main.oooservers.kro.kr/bot.sh4Offlinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/hidden.shOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/goaheadOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/thinkphpOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/awsOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/hnapOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/zteOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/pulseOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/huaweiOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:21http://main.oooservers.kro.kr/lgOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.arm6Offlinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/zyxelOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/realtekOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/jawsOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.mpslOfflinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.x86Offlinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.arm7Offlinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.ppcOfflinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.armOfflinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.arm5Offlinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/gpon443Offlinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.mipsOfflinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.m68kOfflinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/bot.x86_64Offlinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E
2025-05-06 13:00:20http://main.oooservers.kro.kr/yarnOfflinebotnetdomain censys mirai ext moobot sh ua-wget NDA0E
2025-05-06 13:00:19http://main.oooservers.kro.kr/bot.spcOfflinebotnetdomain censys elf mirai ext moobot ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-05-19 11:07:36b0021b02e93fff1e0a28e799fadb027f75339afb1f1a93f3c03552b71709e993sh 
2025-05-19 10:56:477cbd0af522e867c269dbeee726a285435d151e545659a0760ad35b9802fc4590sh 
2025-05-19 10:53:328535dab6e4b22df990a2f0287db2b4cd5661720daa449a186e42b45e6b2ba91csh 
2025-05-19 10:52:52c287bc8d3565017f3fe8aa740a00297f664b52504df224a16494fd692d84b45csh 
2025-05-19 10:51:10afe347ea9026aec7b4eb18bb09a1cbb5289e59c6b083fe11a49b80eb75b7279bsh 
2025-05-19 10:44:119620cb7ed0ab21d086792eefa71bf36be4352839bc61b89f77cc493faaeba129shMirai
2025-05-19 10:38:20b88eafda532abd3c6a06367c916b3028236d635eb8535cb9856041ebcc252e6esh 
2025-05-19 10:35:172ec9807578e979689eb1a8a897dccbcefb3f2b97bab4e6487c27c4a31e9cbb43sh 
2025-05-11 13:51:185086f4d3eff992a3c5c5936266cdd2ffd8a3952f49b8e58b40c44e9ea5619d55shMirai
2025-05-11 13:43:23270cf60b440d9395bbb009c56bb65d58f13e3f180096248d6fba09386a231dddshMirai
2025-05-08 11:34:20db1fba877499f081df7b12b12ba0012e416114793e5e78909d543bbbdb492b63sh 
2025-05-08 11:22:0022069de11c7c562f50d28aff517822863ba78aea80119a9d8fb855cc8ac37ecdsh 
2025-05-08 11:03:38bdebfdc5b28a0bce50be6afd0c57a52ef8fe17f675d61eaf698b4c0f467a2fd1sh 
2025-05-08 10:49:441e19810a813531e95ba69961e1616e836080e8f6af865e3574357d1ffa20cde0sh 
2025-05-08 10:46:2076e88125ebc60c2929216f4e715b4ea66f4a405a2b35a50f59e9a0ac0ae1ab10sh 
2025-05-08 10:40:2860fc35b2a368ea956c7c11f35c999b938f66d21c2a21ecbb7c861c41a19470abshMirai
2025-05-08 10:37:26f87f437a0ac8fc731fe19e0910e220b75593672972ff88477d9f4ed155cfa73ash 
2025-05-08 10:29:40a135652096d9a02c278d0c0caf31370083e5b40ac0f1535b51d8bb2c6449d2b4sh 
2025-05-08 10:22:24e8bdf18e2c76dab34c3ae4a86ff7debf306b339f5ec5b9e85b1c7b2aa1d0f708sh 
2025-05-08 10:20:12bb8b9e098beb52ab67f62f2e4b11ebda7753ac22ecfbbdb4d493447565b29d87sh 
2025-05-08 10:15:2821420692de8be749bf26ff0b17b3ce69328164e55f7a8098f1d6612a5267c7ccsh 
2025-05-08 10:04:3619cac7b258deda206c45247eb1c54271f98cb33b9cbace149044cab7d0523fc6sh 
2025-05-08 09:51:04d77d019977cc00426b62835ff707059fd0f303de46493ad2dcca643d93a23ed5shMoobot
2025-05-08 09:15:209e84cef8a7a1c4276170fbc5de4a478416a8cf9d56f9a8dcaca8a17e67c9d8a0elfMirai
2025-05-08 08:54:55fcd6ea78c0a4309a53096c3e5a8fdd41e06d60d851a971e37a71339baf0585f0elfMirai
2025-05-08 08:41:403fc8b3e4234f42cf021fb0e61580df7b148921641c8258b2dc489578ef66baeeelfMirai
2025-05-08 08:34:48977e2623f7df729a8b9ae26e3749ff0becb4ca73e375a772c5189356efdf877felfMirai
2025-05-08 07:38:028bf7021542d113ab9ac362222ee7d4b8501d2cb21d7d016489b94fbd3daf2504elfMirai
2025-05-08 07:31:49caa10555706395da788270e9e40d7e92b12856c23f2879ac106496385c091a27elfMirai
2025-05-08 07:12:192896c0dbd88bc18dc87d9fdeefb6e116b46792bf2d641eb527d490ec327e9f50elfMirai
2025-05-08 07:01:35b420d329868a4eef429f325b90479e74e8c1332950334daaf8a17a1e077873c5elfMirai
2025-05-08 06:57:3912421ba1eb13fb7de46ebeb60e5cda4b9b065713ff17b8718e84d7187a1473a4elfMirai
2025-05-06 13:00:26669c024055a447743cc20df0560f94828335e9d1eec71c1720340931064427d1elfMirai
2025-05-06 13:00:21e7f255c5493f828a0d7210908c51557fb545125a8d4592c77947a28c56c3c370shMirai
2025-05-06 13:00:21d4192638e21381b6eab31cd7fbeb8838ce353a5e4c65549fd2946c91284d5accshMirai
2025-05-06 13:00:219b8a5c0bcd417c165b422fe770f1725ba9ecc97de8a7835ce504893efc4b1d36shMirai
2025-05-06 13:00:21c2d6d58eb799edffda8b28de80f3774448e8dcc3a60bf60dc03e083ac6788d7fshMirai
2025-05-06 13:00:21dc8f745dfce8e79c312faf2047bccceeb677fed6e75e36dd2047a9aa95278282shMirai
2025-05-06 13:00:217bf6aab258c786baf87c877cacd66814c43a64bdaec3c5891483c3f34f95540fshMirai
2025-05-06 13:00:214a9b7ff3a7f778dfe95457db4f9edeeb18fb7378a85f9f87ea70708d4cfd3d84shMirai
2025-05-06 13:00:216b2291abd127acc3d1ce961ed4775e76719c3a262d476e1f4032e6938986644dshMirai
2025-05-06 13:00:21093d295423c83230502c23b8962ca4e182f3d550e7de3552b682602b53c6b3a6shMirai
2025-05-06 13:00:206acd419809c04ca20437ce71af1f90f92ee8550de45ec675dfadb338f9f780eeshMirai
2025-05-06 13:00:20081023d57a6212be002f12e3abc59cf9bcf596aaaf64e25778499a9d36ae8259shMirai
2025-05-06 13:00:206105110ec6f6c96b6ca1f14fc32fe7469ac4b3ff57dc5a49c9a0b9698f8978d9elfMirai
2025-05-06 13:00:205b774fecf7bf25c2dd2d1c5b901b420231c202585f9faeccf9b9aa3bb821606cshMirai
2025-05-06 13:00:20a6e59bb6c8313ab056702484643c26cfdc2d0cc30c9eb11730528ff162f88c4celfMirai
2025-05-06 13:00:209ac883e9d3547028c50d2be65753a502fec5aa011c395e73a0ab2db2aaa4363eelfMirai
2025-05-06 13:00:203b581d612ba331c80d7ddc5830edc1c0e67a9ca7e79d7d171e9ceaaeb0d79af4elfMirai
2025-05-06 13:00:20a3a024e45097d3af8753f9fe5ae3c0fef2fd5db29e267dbfe989d5de4b0ce37delfMirai
2025-05-06 13:00:206105110ec6f6c96b6ca1f14fc32fe7469ac4b3ff57dc5a49c9a0b9698f8978d9elfMirai
2025-05-06 13:00:19acca8824ad7b62c5baabb789d4b998e96a9984e8fb261b082a08e552ec69474aelfMirai
2025-05-06 13:00:193f00302f1e74cc2a693bc9d1abd17e4e172e47a497213bbf85e067c890c81445elfMirai
2025-05-06 13:00:19ed75f00fe47bd2c43f0fcf451c5c2eff97422aa17f9883ec565dc174515bb4f9shMirai
2025-05-06 13:00:19aa8f6d520c87106db4cd824f7af44ef75b5b2000adc3e709e38211e60e9d1b36elfMirai
2025-05-06 13:00:197b302ebc00e3a190e94b8ede8e81f760785e8c30538f89cc8ce05e249db27bb4elfMirai
2025-05-06 13:00:19920c23ede85dc9805c2cdb594dd0eb4a440a53fe0a1af132039174c937cd7443elfMirai
2025-05-06 13:00:191dfac7c354c820d8f4fc770af6af48e7cfcf13bcb01ceece41946dd5442c4373shMirai