URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 156.245.13.61
Firstseen:2024-04-29 10:51:03 UTC
Total malware sites :6
Online malware sites :0 (0%)
Offline Malware sites :6 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-04-29 11:15:25http://156.245.13.61:8000/read1y.apkOfflineopendir SpyNote abus3reports
2024-04-29 11:05:28http://156.245.13.61:8000/ready.apkOfflineopendir SpyNote abus3reports
2024-04-29 10:55:33http://156.245.13.61:8000/8443nobeaconOfflineopendir Sliver sliverc2 abus3reports
2024-04-29 10:55:32http://156.245.13.61:8000/8443beaconOfflineopendir Sliver sliverc2 abus3reports
2024-04-29 10:55:07http://156.245.13.61:8000/windowsVirus.exeOfflineexe opendir Sliver sliverc2 abus3reports
2024-04-29 10:51:37http://156.245.13.61:8000/replacePara.exeOfflinebackdoor Cobalt strike ext CobaltStrike ext opendir sliverc2 abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-06-01 12:29:36dcf7e926dbdc8773107b7638ce1b5241d072dcf513a97be9927630dc417a012czip  
2024-05-30 12:50:375c54c4a566054a18ff6acdd5e1318447d930819993c1869ac31076ff0dc7c5b1elf  
2024-05-29 14:00:2036902dfc02244bcea4027f918739288203d2024f26a9e5724effdb31b9a56f02exe Sliver
2024-05-29 12:24:299f0ebadf640de50538ac962452361b03712882cf92e438609f187945753a87c4exe Sliver
2024-05-27 05:44:224f4edca2de6a9122c5c69cf25a536e461b0e081078c5e33f7354e098f83bb7cbzip  
2024-05-27 04:11:291e54d0154051338706e7af9a35ae4bd9ad1f2cfd43d40316361a61cc5959c852zip  
2024-05-26 14:08:29f8f8934e8efbb4bfadf63ac84038269c825a4845cc93c2b6daadc53b9ac94531elf  
2024-05-26 14:08:1001c3cbd453a8353816fdefd8c19a8a9dcf4ef546428ac569832e40b5a6ba7569exe Sliver
2024-05-24 12:46:07ce6afae44d23dbd8577cb9afa300a643ab05130f3d5bb9001cddeaeb197a82c1elf  
2024-05-24 12:43:51eb9ade77e32ae086e784b5424286008a7524f71032578d1602e461682a33f127elf  
2024-05-24 12:43:4861d78245c068bc626e0cc7b0bd5140c50eef8504f98db4813e539ccc5e44017aelf  
2024-05-23 07:05:162e9d05f02ac8c341a1d499dbd8585f6e82a071d81e2da226b244eb2da5645253zip  
2024-05-22 06:50:18bb1cbb9ada1c291100ab04ff7cbda0840efe456d90e8c585cf6d935018e274d7zip  
2024-04-29 13:19:227f51e086ad58edea69aa17742eaf7dc2e92816213449789c5cf64dc765a045c3zip  
2024-04-29 12:37:50def4991abb346723efb1251f672d1c9babea5baf62a60fe5d4d79d78b52de529zip  
2024-04-29 10:55:3382e7dd63f21d794e5925d309ca68adfad60895e89977cffe80d261884220a9c2elf  
2024-04-29 10:55:32280adbca100331a581e310157a6f9f2e723ad6785b5ac3c764f8bd9ee9a0defcelf  
2024-04-29 10:55:076853dcea12edeb1629297d5c86b7ef4cf8945421059fe3675615614a6cb6430dexe Sliver
2024-04-29 10:51:32c401c57365e57f1bc8d84f3e42685792b6fa6f55e91bbfdca1b170b64299efbeexeCobalt Strike