URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 172.245.119.43
Firstseen:2021-07-22 15:16:03 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-07-22 15:16:05 172.245.119.43172-245-119-43-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-07-26 18:28:04http://172.245.119.43/65/vbc.exeOffline32 exe Loki ext zbetcheckin
2022-07-26 15:37:04http://172.245.119.43/55/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-07-12 09:42:04http://172.245.119.43/receipt/420.docOfflinedoc Loki ext opendir abuse_ch
2022-07-12 09:42:04http://172.245.119.43/420/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-01-27 14:06:04http://172.245.119.43/4411/vbc.exeOffline32 exe zbetcheckin
2022-01-27 10:22:04http://172.245.119.43/344/vbc.exeOffline32 exe GuLoader ext zbetcheckin
2022-01-27 08:45:04http://172.245.119.43/invoice/delivery.wbkOfflineAgentTesla ext opendir RTF abuse_ch
2022-01-27 08:45:04http://172.245.119.43/invoice/invc_shp.wbkOfflineAgentTesla ext GuLoader ext opendir abuse_ch
2022-01-27 08:45:04http://172.245.119.43/invoice/inv_shp0000.wbkOfflineAgentTesla ext GuLoader ext opendir abuse_ch
2021-08-19 14:30:05http://172.245.119.43/d/skin.exeOfflineexe Formbook ext opendir abuse_ch
2021-08-17 19:21:05http://172.245.119.43/d/hot.exeOffline32 exe Formbook ext zbetcheckin
2021-08-17 19:03:06http://172.245.119.43/d/oy.exeOffline32 exe zbetcheckin
2021-07-23 17:18:03http://172.245.119.43/d/pdf.exeOfflineexe Formbook ext abuse_ch
2021-07-22 15:16:05http://172.245.119.43/d/doc.docOfflineopendir RTF abuse_ch
2021-07-22 15:16:05http://172.245.119.43/d/sharp.exeOfflineexe Formbook ext opendir abuse_ch
2021-07-22 15:16:05http://172.245.119.43/d/obi.exeOfflineexe Formbook ext opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-07-27 05:30:55013c273ca25306a5d7a311db906d012bd07d6a69184349a8d517f514abae9890exeLoki
2022-07-27 00:35:58e1979443e065edcbaf354a1b30834cae7a51d693b1da44778208a7619e5bdec6exeLoki
2022-07-26 18:28:048097912134d281982a17e6744241589c88bd6483de4c3fee8e7fdea14e9db25fexeLoki
2022-07-26 15:37:048097912134d281982a17e6744241589c88bd6483de4c3fee8e7fdea14e9db25fexeLoki
2022-07-12 09:42:04b25b3f389cd46e53173c783e7b69372b5dcd967218f2b2eeabcfe5b7b4355fadexeLoki
2022-07-12 09:42:04d40aee8f78268a641b58494b8460ff576d7df29ef6d4174575bfccf3e4c42a82unknown  
2022-01-27 14:06:042d057e936114db95aceee7e01d6d6451da76622f81ec7d3ea495b4557469b89fexe 
2022-01-27 10:22:04243ae30d42e90000b882779fae40e0056eab332b95e2c938446138a80868909eexeGuLoader
2022-01-27 08:45:04084f59705fb0a98883454b511a2939f6ed91e9c04b7a2d7f8cb13ec834ec5215rtfGuLoader
2022-01-27 08:45:047a3188668cd5ef9ed4e17d9f41a9b5eb22690eb9d6151caf9933f121bfbcedbertfGuLoader
2022-01-27 08:45:04047a728d6d2f43dbac1568044523f045058637d3a6821430fecc47284ae1939funknown  
2021-08-19 14:30:0569747996584aba2690d04958b5e2d6446107ae702a0053fd28c8073b4d7c8ad5exeFormbook
2021-08-17 19:21:0522a3ccdeb9ae4b196461cdb81c895ae891e2149af03e44b6ce86c2a1bf062947exeFormbook
2021-08-17 19:03:0637882a4a0aaf84e2f3c063de493fedbf2233c31c7bd146c79059dd1ae914e2f4exe 
2021-07-23 17:18:0351c392870e9f21df2154b4e68a901ca1b5d9fccdcf00a4e6fa60ef07b4dfc541exeFormbook
2021-07-22 15:16:04a8680fe6b1b96489aa5331018a095d20a4a9c69f3f46bc2f9d1b011242079ba3unknown  
2021-07-22 15:16:04caff14d450514a35eac5ba34b3e74126360662d7c8fdf60a8008a0e3bb8ed0b3exeFormbook
2021-07-22 15:16:0439c27e2a7ec3b5603e184f041bbb07196f6feb885813500fec5ac5fdefca8e1dexeFormbook