URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 31.210.20.45
Firstseen:2021-06-07 08:14:03 UTC
Total malware sites :33
Online malware sites :0 (0%)
Offline Malware sites :33 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-06-07 08:14:04 31.210.20.45Not listedAS14178 Megacable_Comunicaciones_de_Mexico_S.A._de_C.V.- MXyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-06-16 11:08:03http://31.210.20.45/527/sf5pp16.exeOffline32 exe Formbook ext zbetcheckin
2021-06-16 10:03:03http://31.210.20.45/527/hsoleApp9.exeOfflineexe Loki ext abuse_ch
2021-06-15 09:47:04http://31.210.20.45/527/RFL_026_610_371.exeOfflineexe SnakeKeylogger ext Cryptolaemus1
2021-06-15 07:40:04http://31.210.20.45/527/Cf4pp14.exeOfflineexe Formbook ext abuse_ch
2021-06-15 06:51:04http://31.210.20.45/527/s35jp000.exeOfflineAgentTesla ext exe abuse_ch
2021-06-15 06:06:04http://31.210.20.45/527/CossoleApp2.exeOfflineAveMariaRAT ext exe rat abuse_ch
2021-06-15 06:06:03http://31.210.20.45/527/IMG_077010168.exeOfflineexe SnakeKeylogger ext abuse_ch
2021-06-15 06:06:03http://31.210.20.45/527/4243pp14.exeOfflineAgentTesla ext exe abuse_ch
2021-06-15 01:07:03http://31.210.20.45/zch/img_0110168.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-06-14 12:02:05http://31.210.20.45/zCH/RFL_022_610_377.exeOfflineexe SnakeKeylogger ext abuse_ch
2021-06-14 11:56:03http://31.210.20.45/zch/img_23_61_78_802.exeOffline32 exe Loki ext zbetcheckin
2021-06-14 08:01:04http://31.210.20.45/zCH/ConsoleAa16.exeOffline32 exe OskiStealer ext zbetcheckin
2021-06-14 05:50:03http://31.210.20.45/zCH/IMG_003_166_372.exeOfflineAgentTesla ext exe abuse_ch
2021-06-11 06:59:04http://31.210.20.45/1xbet/rfl_01098752.exeOfflineexe Formbook ext zbetcheckin
2021-06-11 06:09:04http://31.210.20.45/1xBet/IMG_061_7308_11.exeOfflineexe OskiStealer ext abuse_ch
2021-06-11 06:07:04http://31.210.20.45/1xBet/dgeApp17.exeOfflineexe Loki ext abuse_ch
2021-06-11 06:07:04http://31.210.20.45/1xBet/IMG_052_11_67_03.exeOfflineexe SnakeKeylogger ext abuse_ch
2021-06-11 06:07:04http://31.210.20.45/1xBet/290-App19.exeOfflineexe SnakeKeylogger ext abuse_ch
2021-06-11 06:03:04http://31.210.20.45/1xBet/RFL_0769002.exeOfflineexe Formbook ext abuse_ch
2021-06-07 18:45:04http://31.210.20.45/10/nanno1.exeOfflineexe NanoCore ext rat abuse_ch
2021-06-07 08:28:03http://31.210.20.45/10/BTL_01880433.exeOfflineexe SnakeKeylogger ext zbetcheckin
2021-06-07 08:27:04http://31.210.20.45/10/RFL_0570103064.exeOfflineexe RedLineStealer ext zbetcheckin
2021-06-07 08:15:06http://31.210.20.45/10/IMG_0001_205_60_37.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:15:06http://31.210.20.45/10/9011.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/RFL_06601287.exeOfflineAgentTesla ext exe opendir abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/BLI_057702308.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/RFT_056_17_30_81.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/BLI_0610_36_31.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/BLI_0617851034.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/IMG_52_67_21_33.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/BLI_05110637.exeOfflineexe opendir OskiStealer ext abuse_ch
2021-06-07 08:15:05http://31.210.20.45/10/RFL_0731_60_127.exeOfflineexe opendir SnakeKeylogger ext abuse_ch
2021-06-07 08:14:04http://31.210.20.45/10/11222.exeOfflineexe opendir rat RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-06-16 11:08:032cc8b68aff95a623ec9c5b66e691346a4de00145f28a31125ae68442cee44201exeFormbook
2021-06-16 10:03:033832dd7fd3eec27f3bc8c6c05597318610c1688284cf700123b3550216ecf221exeLoki
2021-06-15 09:47:048cdbdc48eeff6dbd8b3cf2bcbf91b4c58c5479e8c3779f36debdd3856f17b185exeSnakeKeylogger
2021-06-15 07:40:04fe688e4ea10286585515b497ff637cddfb0525f802afe8d1ddfcdcd1d6f0ee7eexeFormbook
2021-06-15 06:51:040ea60776afead04e4eaadc7428b9a200ce16c4c2f43691c089db073e4d566f8aexeAgentTesla
2021-06-15 06:06:04cc47a9cd21127f53bdb494d7229bae248aa5a4140e7a70a9f6c521741f6ba477exeAveMariaRAT
2021-06-15 06:06:037ee7904969171bddb151071e7b02b14f7f9a560e25ba461c360a3f6b41016df0exeSnakeKeylogger
2021-06-15 06:06:03cdb260bc1d56435c3bd52fe7d5f5f153d8cec4d52450bb53d7db1c669e309095exeAgentTesla
2021-06-15 01:07:03280626c6a1b49b72197144e8b287544f316ffb82fbc6133c1cc51d4f77437660exeRedLineStealer
2021-06-14 12:02:043390c123938c77d21a6ae1dc750265427ea0fb5f5dd3571a9f2dcb069ee66812exeSnakeKeylogger
2021-06-14 11:56:03f45bfd36a12ca3ee1b05b0e05889e8be39b08a4beed3614927e1563d34c1577aexeLoki
2021-06-14 08:01:04fac2fa827e763dfcc0b5baf189dd050db2dae4d731ec54a208c2238d4f7b55e9exeOskiStealer
2021-06-14 05:50:0308c7314bebaa8766553ecedf92db572d0c434168dd9721967c9d11a48ca4e679exeAgentTesla
2021-06-11 06:59:04931959c2c56185581ab2639948e3e207c5cb3c1e1c0225567c31f03a5b39e65dexeFormbook
2021-06-11 06:09:040d0e571bf5bc85d8685228a91bc7e4d087df034ee1a089e24b57057e5767b9c4exeOskiStealer
2021-06-11 06:07:042c4029189010085712385bb7329bf0a10851ddec9c9849e60a94962896fcdfe4exeLoki
2021-06-11 06:07:04109030f50fc7606a5c8aa761d79511c393e5c730607e5bfdce9a761e9b4b9c89exeSnakeKeylogger
2021-06-11 06:07:049448c12a9d9d81d61ac8a3976b433803f2c5a63abe8cb6e74b323ffa3d8356a1exeSnakeKeylogger
2021-06-11 06:03:041754283e0b6bbbbeb69f165e54e3795d3e34ca14aa7bd8bd3b7dcdd97f7dfca8exeFormbook
2021-06-07 18:45:049a0ae5af59b2556ccdf876c973c70e5fbea0331bf6bb090183d502d0e92e3faaexeNanoCore
2021-06-07 08:28:03a4c009ec06d535e7707eeee805c3d00914a599c15b1f7a290d1475a7b17b307dexe SnakeKeylogger
2021-06-07 08:27:04a928e62b289252e6f8188cafda60890e7f6cbcc3dea618ec0570197f2c4d36daexe RedLineStealer
2021-06-07 08:15:065b9d89df2c09b063e502bba2666136656c4bbb088a3bb2025248b1d735384208exeSnakeKeylogger
2021-06-07 08:15:05fe1e23f8893efd1e0dd909e18794609ac8366a6469e44ff70ca8d514833804e5exeSnakeKeylogger
2021-06-07 08:15:05535acb3441a0f17e2a2971a01fc832f397905ce43dc5f5b81556a203acd654b2exeAgentTesla
2021-06-07 08:15:050fa79f489585f59b7204198685d170ef6596d793407f09cf1f3b83bb8b9ce9cfexeSnakeKeylogger
2021-06-07 08:15:05f3f453429fe95e3fd4c3669817511ce52d23061420b1b19c581fd33079055626exeSnakeKeylogger
2021-06-07 08:15:05f76b399147e5918bc895e87a4cf041faee2a9e17970fbd54d41b4e4932c95b20exeSnakeKeylogger
2021-06-07 08:15:05cedeea7372d860671e08fb59cae1037053332c82c6ed8c42b8b4ac9bb894362eexeSnakeKeylogger
2021-06-07 08:15:0573875929249b6d42c502bd5117b0ac0934bf8936922042843f87d6cc02bd6b90exeSnakeKeylogger
2021-06-07 08:15:05245f962fa8ec09944b413f41836d81d8fbc961c34f43e3d8f76cc6324eefe11eexeOskiStealer
2021-06-07 08:15:05193adb1c4bba45e5a5daffd25a1ef5c830b6e6ae34d8aec80482619afd862a35exeSnakeKeylogger
2021-06-07 08:14:04f99a929a42f7c6931aa9e45861aea8e8d24f20da66f8144c7d9e324386364034exeRemcosRAT