URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.133.245.31
Firstseen:2021-10-18 06:26:03 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-10-18 06:26:06 45.133.245.31vds2205622.my-ihor.ruNot listedAS207569 I-SERVERS-NORTH-EU- FIyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-10-18 06:29:05http://45.133.245.31/binance.exeOfflineexe RedLineStealer ext vxvault
2021-10-18 06:28:05http://45.133.245.31/gads.exeOfflineexe RedLineStealer ext vxvault
2021-10-18 06:26:06http://45.133.245.31/video.exeOfflineexe RedLineStealer ext vxvault

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-10-18 06:43:536bfde4a673eabe7104708e9e5e8880b75c75b3696c77e54a2843c14bc2b810ddexe RedLineStealer
2021-10-18 06:29:050e92489b73bb3fbd644629abee74d571b62201f4faf50a15a23875cb9c3bb88cexeRedLineStealer
2021-10-18 06:28:05181c80a7ad3a6a0e4c3cba6a4427a06b59c8f363c86cb8b35c7bb89e81b0a49cexeRedLineStealer
2021-10-18 06:26:05b4be6e15156cf36ee48c4a29bc06899a3953e143f7d61cd1a29083d7367ad9c8exe RedLineStealer