URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.153.34.90
Firstseen:2026-01-27 12:13:04 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-27 12:13:05 45.153.34.90SBL679667AS51396 PFCLOUD- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-02-05 09:05:08http://45.153.34.90/WEB/STEINSECOND.ps1OfflineAgentTesla ext JAMESWT_WT
2026-02-05 09:04:13http://45.153.34.90/WEB/YALLOWSISI.ps1OfflinePhantomStealer JAMESWT_WT
2026-02-05 09:04:13http://45.153.34.90/WEB/FFF.ps1Offline JAMESWT_WT
2026-02-05 09:04:12http://45.153.34.90/WEB/arryaaaaaaaaa.ps1OfflinePhantomStealer JAMESWT_WT
2026-02-05 09:04:12http://45.153.34.90/WEB/grain.ps1Offlinea310Logger ext JAMESWT_WT
2026-02-05 09:04:12http://45.153.34.90/WEB/ENCRYPTED.ps1Offline JAMESWT_WT
2026-02-05 09:04:10http://45.153.34.90/WEB/park.ps1OfflinePhantomStealer JAMESWT_WT
2026-02-05 09:04:10http://45.153.34.90/WEB/arya.ps1Offlinea310Logger ext JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/EAZYYYYY.ps1Offlinexworm JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/DEB.ps1Offline JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/kkmk.ps1Offline JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/aryaphan.ps1OfflinePhantomStealer JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/FAN.ps1OfflinePhantomStealer JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/MODE.ps1OfflineFormbook ext JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/STEINN.ps1OfflineAgentTesla ext JAMESWT_WT
2026-02-05 09:04:09http://45.153.34.90/WEB/STEINSECONDD.ps1OfflineAgentTesla ext JAMESWT_WT
2026-02-05 09:04:08http://45.153.34.90/WEB/eazybim.ps1OfflineAsyncRAT ext JAMESWT_WT
2026-01-27 12:13:07http://45.153.34.90/web/STEINEW.ps1Offlinegeofenced NLD powershell fynn
2026-01-27 12:13:05http://45.153.34.90/web/rod.ps1Offlinepowershell windows Anonymous

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-02-05 09:05:083b39a26469f03e1a41a2cb3ab0f8a43bc05f3ea03ed43ac54139eba9fa19fc16ps1AgentTesla
2026-02-05 09:04:13a08cde6bab4b2f683198287e9419f0e48918989c6000afb19f70ba0a0fab743bps1PhantomStealer
2026-02-05 09:04:130a08eb9584f6fa1594367d7fd8aa29fd173227458be4718d31ded9066af0c216ps1 
2026-02-05 09:04:124b250434bed12ef47cdaea60072ffb83c48e94d873dcbfae378620499d2ec13bps1PhantomStealer
2026-02-05 09:04:127868d1f155fb7d471cd1a5b1e44784fc5e432e4aabebafc5391c98cd8c85cf83ps1a310Logger
2026-02-05 09:04:12be23fd00727294ea740c43445897c1c49f17683c1c68d11389d4f3c5a9a99cc9ps1 
2026-02-05 09:04:1001afd8f97cb7e6f12bd97f06b862c27398ab81f7387c13b705fdf23050ffa0cfps1PhantomStealer
2026-02-05 09:04:10d5dfede85187855607aee7925e3d51571456e3955e7d4ead33ccbe6d391285a0ps1a310Logger
2026-02-05 09:04:09d1ea4eef81008201f51a8da72e58779b6d89647f93a96155e8c1cd89a1d91ffbps1 
2026-02-05 09:04:090c0a32f550ab253b514075b72bcdf112667a818fb89729d6cc0814b8e370bb38ps1XWorm
2026-02-05 09:04:099c9c2539e73f2ce45d2ec7b8c57e4086382f5101605af8b057e32599e91b0780ps1 
2026-02-05 09:04:09195bcb3c7d1c263ae05679c48fcca088d8fea34d263a8b52a6aa8e225bc1b050ps1PhantomStealer
2026-02-05 09:04:0918351edbd499d635aa72c66aa31134fe3525b89e279aa83a768a7be073a0ff76ps1PhantomStealer
2026-02-05 09:04:09dcb462511b28de7cf8704850134b43309a002e3fac25648760cfeb69ec9b3f12ps1Formbook
2026-02-05 09:04:09543bdbe29635cd71265a6a7f7fd1553ab31822c01f1aac1e9db622b4a22e1c55ps1AgentTesla
2026-02-05 09:04:09f90c39785784b998e9dd6dcba99f9e9e452fadf65b8eb6da36ac0ac89c63f4d7ps1AgentTesla
2026-02-05 09:04:08f297f5a682ff007d9f090e034cdda3bbb5a3d4b71fd3b87a2e7ac61c2e59f88dps1AsyncRAT