URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: netrip.ddns.net
Domain registrar:No-IP -
Domain registration date:2001-06-28 16:04:59 UTC
Abuse complaint sent?: Yes (2025-10-21 16:23:01 UTC to kbussche{at}noip[dot]com)
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-10-21 16:22:05 UTC
Total malware sites :15
Online malware sites :8 (53%)
Offline Malware sites :7 (47%)
Newest active malware site :2025-10-23 05:30:20 UTC
Oldest active malware site :2025-10-21 16:22:15 UTC (Age: 1 month, 4 days, 7 hours, 22 minutes)
A record(s) observed :14

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-24 22:42:11 72.61.125.81srv1144529.hstgr.cloudNot listedAS47583 AS-HOSTINGER- MYyes
2025-11-22 23:26:36 38.107.233.38Not listedAS49791 AS-3HCLOUD- USno
2025-11-22 15:32:13 72.61.56.31srv1139159.hstgr.cloudNot listedAS47583 AS-HOSTINGER- BRno
2025-11-20 21:33:51 31.97.147.189srv892825.hstgr.cloudNot listedAS47583 AS-HOSTINGER- USno
2025-11-10 11:23:36 161.97.149.41vmi2843677.contaboserver.netNot listedAS51167 CONTABO- FRno
2025-11-05 13:06:07 185.137.92.52srv845483.hstgr.cloudNot listedAS47583 AS-HOSTINGER- BRno
2025-11-04 05:54:28 212.85.27.46srv1082487.hstgr.cloudNot listedAS47583 AS-HOSTINGER- IDno
2025-11-03 12:33:29 82.112.240.218srv1084322.hstgr.cloudNot listedAS47583 AS-HOSTINGER- FRno
2025-11-02 22:38:00 213.218.240.20srv1077734.hstgr.cloudNot listedAS47583 AS-HOSTINGER- USno
2025-10-23 21:59:56 31.97.223.111srv1070175.hstgr.cloudNot listedAS47583 AS-HOSTINGER- IDno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-23 10:07:10http://netrip.ddns.net/test.shOfflinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-10-23 05:30:20http://netrip.ddns.net/systemcl/arcOnlinebashlite elf mirai ext morte opendir stopmalwareservice stopmalwaresrv
2025-10-23 05:30:20http://netrip.ddns.net/systemcl/x86-DEBUGOfflinebashlite elf mirai ext morte opendir stopmalwareservice stopmalwaresrv
2025-10-23 05:30:20http://netrip.ddns.net/systemcl/spc.spcOfflinebashlite elf mirai ext morte opendir stopmalwareservice stopmalwaresrv
2025-10-23 05:30:20http://netrip.ddns.net/systemcl/sh4.sh4Offlinebashlite elf mirai ext morte opendir stopmalwareservice stopmalwaresrv
2025-10-21 16:23:17http://netrip.ddns.net/systemcl/arm6Onlineelf mirai ext tolisec
2025-10-21 16:22:20http://netrip.ddns.net/systemcl/arm7Offlineelf mirai ext tolisec
2025-10-21 16:22:20http://netrip.ddns.net/systemcl/ppcOfflineelf mirai ext tolisec
2025-10-21 16:22:20http://netrip.ddns.net/systemcl/m68kOnlineelf mirai ext tolisec
2025-10-21 16:22:19http://netrip.ddns.net/systemcl/x86_64Onlineelf mirai ext tolisec
2025-10-21 16:22:19http://netrip.ddns.net/systemcl/armOnlineelf mirai ext tolisec
2025-10-21 16:22:19http://netrip.ddns.net/systemcl/x86Offlineelf mirai ext tolisec
2025-10-21 16:22:19http://netrip.ddns.net/systemcl/mipsOnlineelf mirai ext tolisec
2025-10-21 16:22:19http://netrip.ddns.net/systemcl/arm5Onlineelf mirai ext tolisec
2025-10-21 16:22:15http://netrip.ddns.net/systemcl/mpslOnlineelf mirai ext tolisec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-23 10:07:10bcd340e7466ec0198ad202bff359e50478caead3b7ac00995bc54ecb2bfda280shMirai
2025-10-23 05:30:2052152844e2838f1d3a00c5b8c416356b52994633c1b50365a7eba114f2468b97elfMirai
2025-10-23 05:30:200bf2ee5461bdd7d430bf7e43bb37e2e8e9bca5e44b79afac07cfe5ab344e0e9belfMirai
2025-10-23 05:30:20fbd683cb0e52f396d54fcb77c5af4cbc904e26ff5027b4dc39a4cac191f5a137elfMirai
2025-10-23 05:30:20ea27ca58adb96c761eb3ecfbe3fcd16ab693802939be391d14b0da7a69ef181delfMirai
2025-10-23 00:05:0376f40915e3bbfcd021903f45af774295d1781c327addbcabb3b5bd35da28ecb6elfMirai
2025-10-22 23:38:08a8e6f02362f973adda0cf4dcbc1c5c3809ee7477a7967287893457b8c5eb02b1elfMirai
2025-10-22 22:58:11dfd02ed59c95575642af97a5a34c18ec7be4a61872e339720bba3286d6dbc80delfMirai
2025-10-22 22:25:596f83f9621bd8b0e62a71359b184969f147b0046328455d84a8f20aa1a7ad0faeelfMirai
2025-10-22 22:23:4315c555f6d2014a41eb89f2779f43d1fc11677f501a3219cd3aa72bd0619a2849elfMirai
2025-10-22 22:02:246f83f9621bd8b0e62a71359b184969f147b0046328455d84a8f20aa1a7ad0faeelfMirai
2025-10-22 20:27:08a5357cb8f6566613be9393a2def399b617ef91c2bc5ead8b8c1ff0f50d3f8dd5elfMirai
2025-10-22 18:01:10452a0c93f439b4eeb230d8a3b2b01934b286283bdcc509cc56f09734f1b667edelfMirai
2025-10-22 17:31:293e98eef752fb14582bfd0f70e00ae5f1b2e7ccb06b32597053c6ad8f0e591daeelfMirai
2025-10-22 17:17:43c3f7cf4b69be7bcc3f70465622a093198c73174902d8dd8dfde516f161ba4569elfMirai
2025-10-21 16:23:17899c7e47c4e8f921e14bed7dcca677ed995ead6369168433011cac67ef6e5a59elfMirai
2025-10-21 16:22:20527debaef309134677a1c3a450dc5aea1f3a2a6f742fad86a20c80274c749630elfMirai
2025-10-21 16:22:20dcd7d4b917223e33897da06b7fdb676d16aa4d7afc0276bb4525c275b0a45b10elfMirai
2025-10-21 16:22:20b819a17fd9314f13890dce05291b4c14b40477f0546c7481b4c2af576928244eelfMirai
2025-10-21 16:22:19dc49d000be3daa749c372da39aad50bc49e8d944c7c868fb70b7d15e159d79d3elfMirai
2025-10-21 16:22:19d167fe5abe306825e029bd799bb645048ccae15dca31ea4ac9fcb8b416142a3aelfMirai
2025-10-21 16:22:190aa6fd4f78bcee9f77a93153de85f0db4aa2e42464afcad9564ef46528697d44elfMirai
2025-10-21 16:22:19d167fe5abe306825e029bd799bb645048ccae15dca31ea4ac9fcb8b416142a3aelfMirai
2025-10-21 16:22:194b3fafa6af227c69f3164a2b4f85e7024361a714347c7f691099ed80736916abelfMirai
2025-10-21 16:22:15c5da1b833565988e4bb1729244b07d55ff21148392a7143ff5aab70f43788d6belfMirai