URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.131.66.20
Firstseen:2024-08-05 16:25:05 UTC
Total malware sites :5
Online malware sites :0 (0%)
Offline Malware sites :5 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-08-05 16:25:15 45.131.66.20spf6.piper.ccNot listedAS213250 ITP-SOLUTIONS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-08-05 16:26:10http://45.131.66.20/ts.exeOfflineDarkTortilla exe abus3reports
2024-08-05 16:25:18http://45.131.66.20/mtx111.exeOfflineexe PureLogStealer abus3reports
2024-08-05 16:25:17http://45.131.66.20/skx111.exeOfflineexe abus3reports
2024-08-05 16:25:15http://45.131.66.20/111/555.exeOfflineexe Rhadamanthys abus3reports
2024-08-05 16:25:15http://45.131.66.20/rh111.exeOfflineexe FlawedAmmyyRAT abus3reports

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-06 06:17:37071c1c9433526348994ca19a90f2edd35057c1a17e26960136af25dcddd526ffexe  
2024-08-06 05:08:1271ec9a4998a34dd68f295b53408f39ede981aacb0aacaad0e167dca9d9d86cdcexe  
2024-08-06 03:56:55d04f6bf3ce52509913e638eae368c0823b063553d9a687fe0b5793349ea0fbbaexe  
2024-08-06 03:40:1226deb24bebdf3ef7a08ac078b8877e083190664e655de4272051a06b32bccdf2exe  
2024-08-06 03:24:21addc608e9894ba0fa7093bcce4c218047ffb41a85212261b93a4ca5592f464c7exe  
2024-08-06 01:55:378c00cc26090b94bf29e9094df3d2e818abfb60778cbc476b381d1aec54e7415fexe  
2024-08-06 00:11:44c71f3c32260d5fb2d1526fe3f45c75ce53573a82345381ee5e15836107ec1118exe  
2024-08-05 23:33:371bb33db1f2f6dd6b69d3467291ecce87457bee22744848ff44ab1490ee829f5aexe  
2024-08-05 23:15:50128d5793d20ad24f39d940005b68ab9c27887711831fd48773ffee8016b22c07exe  
2024-08-05 21:14:089b0fc7e87641ae80855982801f892b58609cfca973f679964f972cf7d99e3773exe  
2024-08-05 20:00:41a162c3c422c035d954aae9882970c5e3a9822f88f351786c9bc49c2db7ed9fb3exe  
2024-08-05 19:30:5827293240556178ffaa51136afeadb5dd34046abd92a75479762397b794e3d90fexe  
2024-08-05 19:15:05fbf8a85d0acbf3e891939ecbfeade11e445a897277dd41c30bd27abddb7f4d38exe  
2024-08-05 17:40:5564732145f8b389f46eb987ad69455123b54a36d6749e0687f372d711010bc013exe 
2024-08-05 16:26:10c3c28b2f7e33f7e8d92cd950c168c4e91b90146f9da9b8008f97afeedd5b5080exeDarkTortilla
2024-08-05 16:25:1598bd4ef353739dc8198b8c460c5bfb82b412e57d3db1f3180f8f5bf6d3b4a197exe 
2024-08-05 16:25:11ea0c1b448dfd94060600f75faab6f2bb929269cf1a6498859cff129353e5d7daexePureLogStealer
2024-08-05 16:25:10ee573647477339784dcef81024de1be1762833a20e5cc2b89a93e47d05b86b6aexe FlawedAmmyyRAT
2024-08-05 16:25:106064ef6e5e2d1c432491f675e551844c1b99da343c76f5b34c19a8d940b129e6exeRhadamanthys