URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 172.245.94.136
Firstseen:2022-04-01 13:02:03 UTC
Total malware sites :11
Online malware sites :0 (0%)
Offline Malware sites :11 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-04-01 13:02:05 172.245.94.136172-245-94-136-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-05-03 12:38:04http://172.245.94.136/501/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-29 07:18:04http://172.245.94.136/350/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-28 05:54:05http://172.245.94.136/200/vbc.exeOfflineexe Loki ext lokibot ext LokiPWS AndreGironda
2022-04-26 04:27:04http://172.245.94.136/100/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-13 15:22:04http://172.245.94.136/70/vbc.exeOfflineLoki ext Anonymous
2022-04-12 12:05:05http://172.245.94.136/30/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-06 15:39:04http://172.245.94.136/500/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-05 17:55:05http://172.245.94.136/66/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-05 05:28:04http://172.245.94.136/125/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-04 15:30:05http://172.245.94.136/406/vbc.exeOfflineexe Loki ext opendir abuse_ch
2022-04-01 13:02:05http://172.245.94.136/304/vbc.exeOfflineLoki ext Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-05-03 12:38:04a244c9f48051a0de3e4baaf1f6e09e6027d73bd8c4988311b3697d9800178989exeLoki
2022-05-03 04:20:13b3d17b959be07e41497ebe48d403db574b5e5c2e94b9783bf7301ae17c48f71cexeLoki
2022-05-02 14:26:38f2d2638afb528c7476c9ee8e83ddb20e686b0b05f53f2f966fd9eb962427f8aaexe 
2022-04-29 07:18:0467286378272f3092628103421067df2717eb8b6c7e75dee664ae2157b2fe01beexeLoki
2022-04-28 10:53:306a93a157b3bcb0d13e61ace2f3735864c7636bd462569d435590eb5730d45cdfexeLoki
2022-04-28 06:35:0177ce5d839b7c135917a5089c55a3601d16ac8e803506162cb88d2f1c005682fcexeLoki
2022-04-28 05:54:058bf11c49109e41553a01c4845eaacd7dd10826686b2dd3f61b9d2f4526b57235exeLoki
2022-04-27 00:43:151e6b6aae958d6ed9447ffa9eac3ba3f4bb86c75d03c6b99a4cebda25fb033a06exe Loki
2022-04-26 08:31:4090b880c16f514cdfc593723bc127ef3ffe738dafa14493dc62de8039dcde5f71exe Loki
2022-04-26 06:14:507cbc3e5530aea020ed98ad33e0c02aedf0bcca46fbf7db51b858ae0b30159d8eexe Loki
2022-04-26 04:27:043e207688b841d8557a8ff3c065d55364a547e8397620c7f7ab149c2905c8f4bdexeLoki
2022-04-20 06:08:293e8cb15324c45a64c3407429b4f0f8f3f61715c3ccc300782e90fa04530893bbexe  
2022-04-14 05:21:56c3d893baa2a20c57ce145d588d6fce2159d14a2d3fd5ebdda62091c598f24499exe 
2022-04-13 15:22:04536b1a2e43876d21945ef534ad7beeaf57fa0617110306836c4c9cb78b6fe352exeLoki
2022-04-12 12:05:0592bb5012578914468bee4337e356ee6932c50ce7718a6ff7ce5ee89de97cc850exeLoki
2022-04-06 15:39:04ade19f797e084ef6424ffba70fc3a3af4f002b0e1be4639dcbe89913bfed49d2exeLoki
2022-04-05 23:04:584fb69901a619af8f1e33045373fb0fd6691131bc83f40aa46a03805da004f897exeLoki
2022-04-05 17:55:05239caa5edf3e49c63b728f5ce4f0e17bd977f8c7c54d56c809779cd4914d07a1exeLoki
2022-04-05 05:28:04be0f36c9d84234749eddef16a81cbc4b5702c85595f6ee8e234a8c6de2e22788exeLoki
2022-04-04 15:30:04fd2171f04bc95cf31a59a6bc2ba10e77dd7ac824fa4061cf635484620aa28738exeLoki
2022-04-01 13:02:04a4d51a3f59873bd7ccc504fb98c09e0bddc883e1d75dfa89a20550b5448f61f4exeLoki