coolcams.duckdns.org
Checking live DNS resolution...
100/100
CRITICAL RISK
26
Malware URLs
2
Resolved IPs
891
Abuse Reports
24
Active URLs

Threat Intelligence Summary: coolcams.duckdns.org

Risk Level: CRITICALThreat Score: 100/100

Assessment: coolcams.duckdns.org is actively hosting 24 malware URLs across 2 resolved IP addresses. The number of active endpoints suggests ongoing, organized malware distribution. This domain should be blocked at the DNS or firewall level. Malware families associated with this domain include elf, mirai, botnetdomain.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 26 — Active: 24 — Resolved IPs: 2 — Abuse Reports: 891

First Seen: 2026-03-05T13:30:18 — Last Online: 2026-06-15T02:48:30

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

coolcams.duckdns.org has been associated with 26 malware URLs , of which 24 are currently active . The primary threat types are malware_download, malware.

Active threat. This domain is currently serving malicious content. Multiple malware URLs have been identified on this domain. Network administrators should consider blocking this domain or monitoring traffic to it closely.

Associated malware families include: botnetdomain, mirai, opendir.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2026-03-05T13:30:18
Last Seen Online
2026-06-15T02:48:30
Data Last Updated
2026-06-15T05:00:41.552492
Status Activity Timeline (50 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

OFFLINE ONLINE
http://coolcams.duckdns.org/cat.sh
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/armhf
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/powerpc64
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/mips
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/mipsel
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/m68k
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/i686
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/aarch64
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/sh4
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/x86_64
Status changed from offline to online
OFFLINE ONLINE
http://coolcams.duckdns.org/arm
Status changed from offline to online
ONLINE OFFLINE
http://coolcams.duckdns.org/aarch64
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/arm
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/cat.sh
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/armhf
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/powerpc64
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/sparc
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/mips
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/mipsel
Status changed from online to offline
ONLINE OFFLINE
http://coolcams.duckdns.org/m68k
Status changed from online to offline
Showing 20 most recent changes of 50 total
Associated IP Addresses (2)

All IP addresses this domain has resolved to (current and historical). These IPs may host or have hosted malware URLs.

31.56.209.231
338 abuse reports Severity: medium
176.65.139.42
553 abuse reports Severity: medium
Malware Classification
elf
Malware family "elf" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
mirai
Infamous IoT botnet source code released in 2016, spawning thousands of variants. Responsible for record-breaking DDoS attacks exceeding 1 Tbps. Spreads by scanning for devices with default credentials. Target routers, cameras, DVRs globally.
botnetdomain
Generic botnet command-and-control infrastructure. Domain used to coordinate infected devices, issue commands, and exfiltrate stolen data. Part of distributed botnet network infrastructure.
opendir
Open directory vulnerability exploitation. Attackers use exposed directories on compromised web servers to host malware payloads. Common technique to evade detection by hiding malicious files on legitimate infrastructure.
ua-wget
Automated malware download campaign using wget user-agent strings. Indicates command-line driven infection attempts, typically part of shell script malware loaders targeting servers and IoT devices.
Malware URLs (26)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

http://coolcams.duckdns.org/aarch64
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/i686
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/powerpc64
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/arm
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/cat.sh
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/armhf
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/mipsel
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/m68k
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/sh4
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/x86_64
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/sparc
Taken Down
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
http://coolcams.duckdns.org/mips
Active Threat
IP: 31.56.209.231
Type: malware_download
First Seen: 2026-05-16
botnetdomain mirai opendir
https://coolcams.duckdns.org/
Active Threat
Type: malware
https://coolcams.duckdns.org/
Active Threat
Type: malware
http://coolcams.duckdns.org/bins/ppc
Active Threat
IP: 176.65.139.42
Type: malware_download
First Seen: 2026-03-05
botnetdomain elf mirai ua-wget
http://coolcams.duckdns.org/bins/spc
Active Threat
IP: 176.65.139.42
Type: malware_download
First Seen: 2026-03-05
botnetdomain elf mirai ua-wget
http://coolcams.duckdns.org/bins/arm5
Active Threat
IP: 176.65.139.42
Type: malware_download
First Seen: 2026-03-05
botnetdomain elf mirai ua-wget
http://coolcams.duckdns.org/bins/arm6
Active Threat
IP: 176.65.139.42
Type: malware_download
First Seen: 2026-03-05
botnetdomain elf mirai ua-wget
http://coolcams.duckdns.org/bins/sh4
Active Threat
IP: 176.65.139.42
Type: malware_download
First Seen: 2026-03-05
botnetdomain elf mirai ua-wget
http://coolcams.duckdns.org/bins/arm7
Active Threat
IP: 176.65.139.42
Type: malware_download
First Seen: 2026-03-05
botnetdomain elf mirai ua-wget
Showing 20 of 26 URLs