URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: proxy.zhalenmsl.biz.id
Domain registrar: n/a
Domain registration date:2025-11-14 14:38:21 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2026-01-13 17:45:07 UTC
Total malware sites :16
Online malware sites :16 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-01-13 17:45:26 UTC
Oldest active malware site :2026-01-13 17:45:15 UTC (Age: 1 day, 20 hours, 27 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-13 17:45:15 202.1.31.175Not listedAS149020 WEBHORIZON-AS-AP- SGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-13 17:45:26http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:19http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:18http://proxy.zhalenmsl.biz.id/1.shOnlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/debugOnlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre
2026-01-13 17:45:15http://proxy.zhalenmsl.biz.id/windyloveyou/wind...Onlinebotnetdomain mirai ext opendir DaveLikesMalwre

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-13 17:45:2676b5daf6bc1527726048d5ee444b5e2d79f99f519a1b290bbada05892cf14d78elfMirai
2026-01-13 17:45:19a1bb22f212902bebe68dfd700ec35da759169060b9ff62bac552037dde65d728elfMirai
2026-01-13 17:45:1864a93c5b0e32cd73f1312dc3d10a9cc63ee26e139ca1f5c9c9d580c120d73980shMirai
2026-01-13 17:45:1517eb2359948a9d523b3c15b97364c0658eb74080c042d319518c9f706accdc15elfMirai
2026-01-13 17:45:15a16884f22c23b1eaf3cf4592db352d6059a8a7cb755bd99f5843bcaa77950d8belfMirai
2026-01-13 17:45:15c90c08d68c7f3844b7055f345eccca551e589bbe98a23b36c64370c159fa6679elfMirai
2026-01-13 17:45:15bcfd1c9b186666483509dba5d0377d67e440449b7699f4304509855346cb6564elfMirai
2026-01-13 17:45:15458a71e1d9feb07eeb09cb2cc4b8dcabd9aaa89774687ba9aad1e6f1bd518d8aelfMirai
2026-01-13 17:45:1518bd66490fafffe9126ffeb8d39dc9bbdd0c29b84f551a76572195368182ca72elfMirai
2026-01-13 17:45:15e92795e5c1b34a77a7233a5d184e29fb7149c120a05c3d105c998e2be63a2b42elfMirai
2026-01-13 17:45:150bbed3bade9eb683c8de2830666302183923641e7d83a7fa4c5bdcf2a7a53d1eelfMirai
2026-01-13 17:45:1501563d7779828af88279dac3d95cd3332434f5be7963254e75dc4756cdb6235aelfMirai
2026-01-13 17:45:15cb52ae19dce8f112409e790bdffae28ae8514edd23e17f38b48b8df4bce83daeelfMirai
2026-01-13 17:45:146d0329f2cdaf6670732328f9f9ffd0282af6aa99e284643e44bf9b33f70cd9e9elfMirai
2026-01-13 17:45:143cf072e8e36a2a49b1bc3dcf6fc1564fb72792af672906010282a19d3e118af2elfMirai
2026-01-13 17:45:1415d22fe6d17b10f7dcd5e5336526743926031355bc9b396a6644d59890b3fa71elfMirai