URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 143.20.185.245
Firstseen:2025-11-26 09:40:06 UTC
Total malware sites :18
Online malware sites :16 (89%)
Offline Malware sites :2 (11%)
Newest active malware site :2025-11-26 17:12:07 UTC
Oldest active malware site :2025-11-26 09:40:10 UTC (Age: 15 hours, 34 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-26 09:40:10 143.20.185.245Not listedAS214209 INTERNET-MAGNATE- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-26 17:12:07http://143.20.185.245/windyluvexecutor/debugOnlineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-11-26 10:35:15http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:15http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:15http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:15http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:15http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:15http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:13http://143.20.185.245/windyluvexecutor/executor...Offlineelf ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:10http://143.20.185.245/windyluvexecutor/executor...Onlineelf mirai ext ua-wget abuse_ch
2025-11-26 10:35:07http://143.20.185.245/windyluvexecutor/executor...Offlineelf ua-wget abuse_ch
2025-11-26 09:40:10http://143.20.185.245/lol.shOnlinemirai ext script geenensp

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-26 17:45:167c9480d487e66d371405f0061e7523dbda14fa19f020f9e847aaa45455c5523csh 
2025-11-26 17:12:07261fa51d601b568e85af693dd2ecbdfcf44971faba9e153156c4574f351efa53elfMirai
2025-11-26 10:35:15a1848e073dcd7fe81f80798fb334b22850b1a479bb4d9b37568f643c0d365ba9elfMirai
2025-11-26 10:35:152bbd5d07534838e17a67fc04a354a91da63f32c69a86a097b318d860b3e96f0belfMirai
2025-11-26 10:35:15f171ba7b8e9fabbe29583fac9acd93541911ba0d5d9a7a5e226ae6bc052fdd57elfMirai
2025-11-26 10:35:152ecc7cba2a71a5f9dc84ebd22c6d0d39c85143c4c5f3c70524f5dc09a72a64a9elfMirai
2025-11-26 10:35:15812527b90479bc96521fd1af830f50f423ca2bbd2425032ae667990d34cd14faelfMirai
2025-11-26 10:35:1539ceab7eddf5d287d58933a7c8f868916dfa95bcacbaa2005b790192d2b92e2felfMirai
2025-11-26 10:35:1087c292524eeba3438f9d1bec884386b4655e6b7962de4bce851e9eb26f087152elfMirai
2025-11-26 10:35:10c2a046ea359426c9d013df98fd05f3210b312b7beea51aef17f121eb806d0d7celfMirai
2025-11-26 10:35:10d5fcb0c80275a020c4801ac3f6d09575c23f993e113bee223740750ef0128fa1elfMirai
2025-11-26 10:35:109d498d20111cba7c7e150369ee4e978bd15d5099a9e7bd384e87cfbf78a266e7elfMirai
2025-11-26 10:35:1026da6edd2ab78877aa388f85b2b48d211458ff890d277d174ae7be47ce4bf42aelfMirai
2025-11-26 10:35:103f3016804c38ec622929a19d77a478b75235198636062d1877c3688696fa40dcelfMirai
2025-11-26 10:35:10ab9b0d4b0617ca0be4936579d0fa3c50616aed542f324c5c25cece9080a64914elfMirai
2025-11-26 10:35:10a201236b70d2287baf8ae7b6ef926d57ab5fbee45ad0b0e4e94a20fd722e4849elfMirai
2025-11-26 09:40:08043b3310415a40ca97c5b97712a89bcd7a8766bd5cad9280843302d9901bc24eshMirai