URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.12.32.131
Firstseen:2021-04-27 15:57:02 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-04-27 15:57:05 45.12.32.131free.ns1.sitesblog.comNot listedAS215224 NOVOSERVE-CUSTOMERS-AS- VGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-04-27 15:57:05http://45.12.32.131/44313,6048108796.datOfflineb-TDS dll Quakbot ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-04-29 03:20:24688b469146e50cac6ad3ca31c45a582bc70bc63c7a54402cf90a8b6f7b0cd3ccdll Quakbot
2021-04-28 14:56:13d7ea3c08f5a6606204c797feb32a08028d70700b84fd5092fd51440f8426da64dllQuakbot