URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 172.245.209.195
Firstseen:2026-02-12 17:41:04 UTC
Total malware sites :18
Online malware sites :17 (94%)
Offline Malware sites :1 (6%)
Newest active malware site :2026-02-12 19:00:09 UTC
Oldest active malware site :2026-02-12 17:41:08 UTC (Age: 1 day, 4 hours, 38 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-02-12 17:41:08 172.245.209.195172-245-209-195-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-12 19:00:09http://172.245.209.195/33/svc.exeOnlineexe PureLogsStealer NDA0E
2026-02-12 18:55:13http://172.245.209.195/55/4545fdfgd65d6d6jhgjjg...Onlinevbs NDA0E
2026-02-12 18:51:07http://172.245.209.195/33/scv/mm.htaOnlinehta PureLogsStealer NDA0E
2026-02-12 18:40:12http://172.245.209.195/Onlinecensys RTF NDA0E
2026-02-12 18:40:11https://172.245.209.195/Onlinecensys RTF NDA0E
2026-02-12 17:43:08http://172.245.209.195/tk/jsnewshim.jsOnlineascii opendir abuse_ch
2026-02-12 17:43:07http://172.245.209.195/tk/fdr.txtOnlineascii Encoded opendir rev-base64-loader abuse_ch
2026-02-12 17:42:11http://172.245.209.195/tk/puty.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/mpa.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/way.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/hm.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/nnd.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/sk.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/hk.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/lupi.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:10http://172.245.209.195/tk/wk.txtOnlineascii opendir rev-base64-loader abuse_ch
2026-02-12 17:42:08http://172.245.209.195/tk/prlshim.vbsOfflineascii opendir abuse_ch
2026-02-12 17:41:08http://172.245.209.195/mmm/mk.ps1Onlineascii opendir powershell ps1 RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-12 19:00:09b3e614b5a01c062091955dccf6ebb4b2351875cc4017e90609d8ec5b767e075bexePureLogsStealer
2026-02-12 18:55:138c6eaf2a1f83d6e600fd6abad957f71bbe37d68ed8d8e66995b0911121f23a21txt  
2026-02-12 18:51:072f80cc0fa8d8814e979d7910ddee88e84ece46c1110b7c9f564437bd41bea85fhtaPureLogsStealer
2026-02-12 18:40:1170535e402e399e2743de32189aa712eeb0f8fdb4c2b8daafd01d5fbdaf438ad4rtf 
2026-02-12 18:40:1170535e402e399e2743de32189aa712eeb0f8fdb4c2b8daafd01d5fbdaf438ad4rtf 
2026-02-12 17:43:08b50e370c90617709101cd498e9b9518c7ffc60aafc1effbf2fdc25c3c121f989js  
2026-02-12 17:43:07240f5523c6b3b82fc09029f81a5f3726df5e4508eaafa5054e0f481cd009a582txt  
2026-02-12 17:42:11680abf58fdb3f8352ea23a7eaf70561a092d3cf096d368a243a713b0d34c3a2btxt  
2026-02-12 17:42:106b5f5e7b9a699d72b90e62917a2bda471fb837b3abaf864c3fbdb0059363bb16txt  
2026-02-12 17:42:10240f5523c6b3b82fc09029f81a5f3726df5e4508eaafa5054e0f481cd009a582txt  
2026-02-12 17:42:10240f5523c6b3b82fc09029f81a5f3726df5e4508eaafa5054e0f481cd009a582txt  
2026-02-12 17:42:10240f5523c6b3b82fc09029f81a5f3726df5e4508eaafa5054e0f481cd009a582txt  
2026-02-12 17:42:10240f5523c6b3b82fc09029f81a5f3726df5e4508eaafa5054e0f481cd009a582txt  
2026-02-12 17:42:09240f5523c6b3b82fc09029f81a5f3726df5e4508eaafa5054e0f481cd009a582txt  
2026-02-12 17:42:096b5f5e7b9a699d72b90e62917a2bda471fb837b3abaf864c3fbdb0059363bb16txt  
2026-02-12 17:42:096b5f5e7b9a699d72b90e62917a2bda471fb837b3abaf864c3fbdb0059363bb16txt  
2026-02-12 17:41:088f8028d875820d3ee93b3d82dfbbf0cfc9a37400cb8cec5bcd4b893c19c1fa36ps1 RemcosRAT