URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 104.245.241.219
Firstseen:2025-03-25 16:48:03 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-03-25 16:48:05 104.245.241.219Not listedAS9009 M247- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-03-25 16:48:05http://104.245.241.219/txt/sCIPrhZt5Yub9qL.exeOfflineexe Loki ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-03-27 03:52:24353f0431abc35f4de737193828be509e69003e0ba6e917e60aa5ce6c025d98a0exe Loki
2025-03-26 16:41:56803314d516cb803d9c61b7f0df4b49cb3ed68e29ef80b2a2761f4258425a9475exe Loki
2025-03-26 03:42:21b2b9b4ee2a4edc1926c1bfdfa07061968a2e8f3685f5cae15bfbe4723f9156c9exeLoki
2025-03-25 16:48:051ecc198e5201c2c75116d69ff26703342f7b6c854edfbb9c0af6b3271f05a42eexe Loki