URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.135.194.4
Firstseen:2026-04-21 06:13:06 UTC
Total malware sites :7
Online malware sites :0 (0%)
Offline Malware sites :7 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-21 06:13:07 45.135.194.445.135.194.4.ptr.pfcloud.networkSBL679271AS51396 PFCLOUD- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-22 08:50:21http://45.135.194.4:8080/c2agentOffline adliwahid
2026-04-21 06:13:13http://45.135.194.4/vps-agent-linux-amd64Offline adliwahid
2026-04-21 06:13:07http://45.135.194.4:8080/c2.shOffline adliwahid
2026-04-21 06:13:07http://45.135.194.4:8080/simple_agent.pyOffline adliwahid
2026-04-21 06:13:07http://45.135.194.4/install.shOffline adliwahid
2026-04-21 06:13:07http://45.135.194.4:8080/sh_test.shOffline adliwahid
2026-04-21 06:13:07http://45.135.194.4:8080/install.shOffline adliwahid

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-21 11:44:2233eca311773db8873040af1c4806b8c1fcb3bdd5bbc60011eb6f59bfc4917f3belf 
2026-04-21 06:13:13286d2911db3ae69f3f7ece727ec111692c0102a4d033df87f8541771afcfc447elf