URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: vps-3002.onecom-cloud.one
Domain registrar:One -
Domain registration date:2024-06-25 16:11:05 UTC
Spamhaus DBL :Abused domain (botnet C&C)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2025-12-23 06:21:09 UTC
Total malware sites :21
Online malware sites :20 (95%)
Offline Malware sites :1 (5%)
Newest active malware site :2025-12-24 12:38:10 UTC
Oldest active malware site :2025-12-24 12:22:19 UTC (Age: 5 hours, 7 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-23 06:21:11 81.88.18.108vps-2624.onecom-cloud.oneNot listedAS8648 ONE-NETWORK- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-24 12:38:10http://vps-3002.onecom-cloud.one/bins/shadow.arm64Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:38:10http://vps-3002.onecom-cloud.one/bins/shadow.armOnlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:38:10http://vps-3002.onecom-cloud.one/bins/shadow.mpslOnlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:38:09http://vps-3002.onecom-cloud.one/bins/shadow.i586Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:20http://vps-3002.onecom-cloud.one/yarnOnlinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-12-24 12:22:20http://vps-3002.onecom-cloud.one/binOnlinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-12-24 12:22:20http://vps-3002.onecom-cloud.one/bins/shadow.ppcOnlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:20http://vps-3002.onecom-cloud.one/bins/shadow.arm7Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:20http://vps-3002.onecom-cloud.one/bins/shadow.arm6Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/payOnlinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.spcOnlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.sh4Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.arm5Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.mipsOnlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.arm5nOnlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.m68kOnlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.i486Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/asus.shOnlinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/bins/shadow.x86Onlinebotnetdomain elf mirai ext ua-wget BlinkzSec
2025-12-24 12:22:19http://vps-3002.onecom-cloud.one/shadow.shOnlinebotnetdomain mirai ext sh ua-wget BlinkzSec
2025-12-23 06:21:11http://vps-3002.onecom-cloud.one/bins/shadow.x8...Offlineelf geofenced mirai ext ua-wget USA x86 botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-12-24 12:38:095ee3a4aec9a92a62c5d308a2ec541372ab4bacf3fa05e833d880935cf46d0721elfMirai
2025-12-24 12:38:09eb9e1cf68eb14e4adcdfa704496393a5650750460d44a27fc6810a8fb943c18delfMirai
2025-12-24 12:38:097a1849017c0684337d85b2aa8a730c4fee62486f444c675e8414b97c50cfb5a8elfMirai
2025-12-24 12:38:096e01176ce19a409441cadb631f5f0c9b51705a99ebeac50cfae65de383b2e4d4elfMirai
2025-12-24 12:22:19b80c304c154e78c442f468a2d986124c4e14222c343aff4cdd3d332c9ac3822fshMirai
2025-12-24 12:22:19b80c304c154e78c442f468a2d986124c4e14222c343aff4cdd3d332c9ac3822fshMirai
2025-12-24 12:22:19b80c304c154e78c442f468a2d986124c4e14222c343aff4cdd3d332c9ac3822fshMirai
2025-12-24 12:22:1972f8dcac376fa2861c1a6591953d2c4ad3eed9c634938b3a04388603121ac424elfMirai
2025-12-24 12:22:19a9e36e6d5c7b89b86270b0ea4d1363cd83e1f8efdabd7331c76ce3e1c64a3539elfMirai
2025-12-24 12:22:1901a6e4d8e80b7090e1287238fce08de7bf135d537438845cbb3283f0c17f2d95elfMirai
2025-12-24 12:22:19c9b7e82f11bbb447ffd558b840e98e8d4472371545b80b35432b0502447e81feelfMirai
2025-12-24 12:22:199db2cdc377de44600f2bd4ea70114ef56ca00c876e0577899288782fd8b11fbdelfMirai
2025-12-24 12:22:194d5a9a2f2e81daf2490c91bbc8f8a9363cea14da81749fa0131ba80512542b30elfMirai
2025-12-24 12:22:197a84fe422301a21cbbb8dd3cdc0e643ee0b9c1aadffa8c57398fd62ea4b58c4belfMirai
2025-12-24 12:22:194d5a9a2f2e81daf2490c91bbc8f8a9363cea14da81749fa0131ba80512542b30elfMirai
2025-12-24 12:22:195442e5301eab8ab38d0957494067d4b1e5f0df7123945e9fc2a19ca0e82eb502elfMirai
2025-12-24 12:22:190e96a2b051308669018d8a9270e18b63d79348e962a920e4dc25025baac3a753elfMirai
2025-12-24 12:22:19a23fbf034154fb243d6f8971eb5da56a214f2ca58635a9bd1f6bd6d00e371916shMirai
2025-12-24 12:22:196e01176ce19a409441cadb631f5f0c9b51705a99ebeac50cfae65de383b2e4d4elfMirai
2025-12-24 12:22:19b80c304c154e78c442f468a2d986124c4e14222c343aff4cdd3d332c9ac3822fshMirai
2025-12-24 01:06:487c4d404b0e75f2e8a13e6d396544a04667a28b0d73f2baf2ee11d715d09c52e1elfMirai
2025-12-23 06:21:11a9687fbc701d10bd212cdd6a4d0bef5e6b239a9de36c1f04801726dca97b097felfMirai