URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.12.32.87
Firstseen:2021-04-19 17:03:03 UTC
Total malware sites :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-04-19 17:03:10 45.12.32.87free.ns1.sitesblog.comNot listedAS215224 NOVOSERVE-CUSTOMERS-AS- VGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-04-19 17:03:10http://45.12.32.87/44300,5396033565.datOfflineb-TDS dll Quakbot ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-04-20 06:07:585275aee738fcebf48813c8d28600462703de1c11d54eda06af951862c89fe6b9dll Quakbot
2021-04-19 21:39:13879e5e28fa4faadfce3f58dcfb5e73d86fd9375e66354cdbe2c5efead0fd0a4ddll Quakbot
2021-04-19 17:03:095925bb4f2e8eaa4144a3583ad7049164a5051a3d1d8b5b38b93119f8f1c77257dllQuakbot