URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.141.58.219
Firstseen:2026-01-28 16:52:03 UTC
Total malware sites :24
Online malware sites :24 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-01-28 16:52:20 UTC
Oldest active malware site :2026-01-28 16:52:08 UTC (Age: 9 hours, 28 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-28 16:52:08 45.141.58.219SBL632422AS213373 IPCONNECT- ATyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-01-28 16:52:20http://45.141.58.219/B.exeOnlineMeshAgent opendir ua-wget BlinkzSec
2026-01-28 16:52:20http://45.141.58.219/OneDrivesv.exeOnlineMeshAgent opendir ua-wget BlinkzSec
2026-01-28 16:52:20http://45.141.58.219/OneDrivesvc64-Dumpster.exeOnlineMeshAgent opendir ua-wget BlinkzSec
2026-01-28 16:52:20http://45.141.58.219/OneDrivesvc64-Transfer.exeOnlineMeshAgent opendir ua-wget BlinkzSec
2026-01-28 16:52:19http://45.141.58.219/3.0_X-Lite_Win32_1006e_340...Onlineopendir ua-wget BlinkzSec
2026-01-28 16:52:19http://45.141.58.219/ServiceHost.exeOnlineopendir ua-wget BlinkzSec
2026-01-28 16:52:19http://45.141.58.219/ServiceHost_1.exeOnlineopendir ua-wget BlinkzSec
2026-01-28 16:52:19http://45.141.58.219/RunTimeBroker.exeOnlineMeshAgent opendir ua-wget BlinkzSec
2026-01-28 16:52:19http://45.141.58.219/WEB_RTC_Update.exeOnlineconnectwise opendir ua-wget BlinkzSec
2026-01-28 16:52:18http://45.141.58.219/Mesh.exeOnlineMeshAgent opendir ua-wget BlinkzSec
2026-01-28 16:52:17http://45.141.58.219/MAYBE.msiOnlineconnectwise opendir ua-wget BlinkzSec
2026-01-28 16:52:13http://45.141.58.219/auth_cw.exeOnlineconnectwise opendir ua-wget BlinkzSec
2026-01-28 16:52:11http://45.141.58.219/wxipp.exeOnlineNanoCore ext opendir ua-wget BlinkzSec
2026-01-28 16:52:11http://45.141.58.219/ss.exeOnlineopendir ua-wget BlinkzSec
2026-01-28 16:52:11http://45.141.58.219/det.exeOnlineNanoCore ext opendir ua-wget BlinkzSec
2026-01-28 16:52:11http://45.141.58.219/UserOOBE.exeOnlineopendir ua-wget BlinkzSec
2026-01-28 16:52:11http://45.141.58.219/updater.exeOnlineopendir ua-wget BlinkzSec
2026-01-28 16:52:11http://45.141.58.219/UniRun.exeOnlineopendir ua-wget BlinkzSec
2026-01-28 16:52:10http://45.141.58.219/wininittt.exeOnlineNanoCore ext opendir ua-wget BlinkzSec
2026-01-28 16:52:10http://45.141.58.219/win.exeOnlineNanoCore ext opendir ua-wget BlinkzSec
2026-01-28 16:52:08http://45.141.58.219/smss.exeOnlineNanoCore ext opendir ua-wget BlinkzSec
2026-01-28 16:52:08http://45.141.58.219/primary.exeOnlineopendir ua-wget BlinkzSec
2026-01-28 16:52:08http://45.141.58.219/onedrivetray.exeOnlineAsyncRAT ext opendir ua-wget BlinkzSec
2026-01-28 16:52:08http://45.141.58.219/winninitt.exeOnlineNanoCore ext opendir ua-wget BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-01-28 16:52:2019cec116f61bb5e7f07ff44fb6bc87127bf07d9c43fcb477475a16641b5ef7caexe MeshAgent
2026-01-28 16:52:20e2bd160a09a1cb83b5810e2a9201946015ba7a8086756bf45911c76044b555e0exe MeshAgent
2026-01-28 16:52:2028067e637f07f6f8b7f07fcc6ef49218f3cf14c48c117b361f7a5170f2d6bc35exe MeshAgent
2026-01-28 16:52:20e2bd160a09a1cb83b5810e2a9201946015ba7a8086756bf45911c76044b555e0exe MeshAgent
2026-01-28 16:52:1982606578fffea202aec7106e8f5095948bedeabd4c7f2497647f28ad9315b2d5exe  
2026-01-28 16:52:19cace381e9f84fa8c23a7bb7121c26c5aa409cd28b6613133f22d2374520c58aeexe 
2026-01-28 16:52:199b15d1a2119c998c4d4015f6fcc6726646b730e9573045fd980ff8fe4c530422exe 
2026-01-28 16:52:19a0482973570c0a5bf17e7b98cb92e0d5a0bc361204af05e4b60c95a99b7d7373exe MeshAgent
2026-01-28 16:52:19f2dc9c66ae297dd8739cb4547ee59ab3e83365265043c3da58c1ad4eede8ea1dexe ConnectWise
2026-01-28 16:52:17a0482973570c0a5bf17e7b98cb92e0d5a0bc361204af05e4b60c95a99b7d7373exe MeshAgent
2026-01-28 16:52:1664f1cc8a4da91db6bc233c606d50fc159e9f4a0bfe2f84707873e7261dc74078msi ConnectWise
2026-01-28 16:52:12d1f82a30ccd32768a10081bc33fa79f3ef981e9665b636d7217381d2acbc307eexe ConnectWise
2026-01-28 16:52:11b89a70f1b581bb4807cb6a7c40146f0b28e2f1469c83bd019c1a37819da85a79exe NanoCore
2026-01-28 16:52:110fc90a024d9bb900bb43ab567cabf32defd4f3b6107f94197baab6b2a11effbfexe 
2026-01-28 16:52:111715d8df581e2cdbd1d27a1e30a20c229e732fe8fb85e7403daac8d603ddc2c5exe NanoCore
2026-01-28 16:52:117fa484d8a7dab9c3dde9a3b18ae31fe9f60a1e6f17334c29f93efe0a8a819425exe 
2026-01-28 16:52:10c5444c6f040fa49183564bbfb146584b61accb74b56be6ec326fa73147cac5f7exe 
2026-01-28 16:52:103bd5484954ad2efcdc3c2dd108d12eadab50841926d244df052df20171fb3282exe 
2026-01-28 16:52:10d301618a42b6368df0dd756ff343fb62ac1b6f7208fcf2b52d5ab2d8272028a7exe NanoCore
2026-01-28 16:52:10d301618a42b6368df0dd756ff343fb62ac1b6f7208fcf2b52d5ab2d8272028a7exe NanoCore
2026-01-28 16:52:06d3a4ce5780a8c445e8b3949142230014aecd56160a7cddb70f2a89a8b36714ceexe NanoCore
2026-01-28 16:52:0658769eaa3332436c673f25285dd951d5b113ed2696daba6ab47e7e0f061ec4a4exe  
2026-01-28 16:52:06a5b5cf28cd778e1e101bde94dd903c0038bb7a0ff0c88275705fec78fd3ad0ddexe AsyncRAT
2026-01-28 16:52:06150dc6dbcb7d60ef0abc79d5b15be1725d5c5ff10a4199a9cf916c5888c3ab97exe NanoCore