URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.159.189.39
Firstseen:2021-12-16 22:04:03 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2021-12-16 22:04:04 45.159.189.39orgagvscp.org.ukNot listedAS14576 HOSTING-SOLUTIONS- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2021-12-18 16:08:06http://45.159.189.39:8080/1/deployement_crypted...Offline32 exe RedLineStealer ext zbetcheckin
2021-12-18 08:08:05http://45.159.189.39:8080/1/Southering.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:05http://45.159.189.39:8080/1/testRLv2.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:04http://45.159.189.39:8080/1/TestOtSupa.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:04http://45.159.189.39:8080/1/Manatee.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:04http://45.159.189.39:8080/1/Stingingly.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:04http://45.159.189.39:8080/1/oTradingPlatform.exeOfflineexe hfs abuse_ch
2021-12-18 08:08:04http://45.159.189.39:8080/1/one_castro.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:04http://45.159.189.39:8080/1/RewGlottidean.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:04http://45.159.189.39:8080/1/castroMozgoeb3.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 08:08:03http://45.159.189.39:8080/1/castroMozgoeb2.exeOfflineexe hfs RedLineStealer ext abuse_ch
2021-12-18 00:33:11http://45.159.189.39:8080/1/setup.exeOfflineexe RedLineStealer ext Cryptolaemus1
2021-12-18 00:33:05http://45.159.189.39:8080/1/a_2021-12-17_20-49.exeOfflineAmadey exe Cryptolaemus1
2021-12-18 00:33:04http://45.159.189.39:8080/1/payload.exeOfflineexe RedLineStealer ext Cryptolaemus1
2021-12-17 21:15:05http://45.159.189.39:8080/1/Caesura.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-12-17 01:21:05http://45.159.189.39:8080/1/build_FullCrypt.exeOffline32 ArkeiStealer ext exe zbetcheckin
2021-12-17 01:15:04http://45.159.189.39:8080/1/Amusable.exeOffline32 exe RedLineStealer ext zbetcheckin
2021-12-16 23:08:03http://45.159.189.39:8080/1/EricaceousBlindness...Offline32 ArkeiStealer ext exe zbetcheckin
2021-12-16 22:04:04http://45.159.189.39:8080/1/1234.exeOffline32 exe RedLineStealer ext zbetcheckin

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2021-12-18 16:08:051ccc0af2e57d00c53b91e8e191a9a3ce4692c87c4ae8a00035323c840f921708exeRedLineStealer
2021-12-18 08:08:0518cd037dafda0a1a6af0cc72a5bfdfbae4a9c78f63708cd4fdd38048f5a4c87fexeRedLineStealer
2021-12-18 08:08:05c4c8179ac2a2be1697ef244e5c8c4e70dd311b0f4a350c6fe1f05ddd69afc1f3exeRedLineStealer
2021-12-18 08:08:04168cf1b514dcd2935f60fd9be6317d2eb3ab32908f3a46d6b7f339109044e8ecexeRedLineStealer
2021-12-18 08:08:0474c5701189877d6ff1cee769cfb34bd211feebbd4ad1e03c4f5c609dffe184acexeRedLineStealer
2021-12-18 08:08:0498a293de8d3eb34cee5e3e8edc9f472323d13a997bdbd2806ac1fe483f5efd14exe 
2021-12-18 08:08:049ae164f0b4984b78928811ea2e6bf7d49dcbdba1fea2f17c0a017df925503173exeRedLineStealer
2021-12-18 08:08:04337436e6e0d05430b7ea701871735f68d3df1e9aaca2dd3e1b4074bac5e9c6f2exeRedLineStealer
2021-12-18 08:08:033dbd5487b19aa019bade16d9061195230b742a45ddb2e411d0e6b7fac6778e17exeRedLineStealer
2021-12-18 08:08:0333ba74ef9c6a96c68a0f95f518df17cfe61126d9605c483100661752440c47abexeRedLineStealer
2021-12-18 08:08:0356132bf8c1be4feeeb6aec15656688659ee0c9861f94519da8b94ced1801f2b2exeRedLineStealer
2021-12-18 00:33:11e237102ecce153410e4609db0ec5986e2d874a5efe4c9ace10bd419e80dce974exeRedLineStealer
2021-12-18 00:33:05bd1ae8b23302a17ef00d7a83024b0d7bcef71a279e98790b60a87c0981ac6ed5exeAmadey
2021-12-18 00:33:0493debd2f5562df361e0df486f3aa3b23ea5fa6e2ed9865a00fa8c2c8ecd758f1exeRedLineStealer
2021-12-17 21:15:0530ea2b66243b336c8c371b34d6588a3c5d08eb5eda6334342c5164098d900a60exeRedLineStealer
2021-12-17 01:21:059aedd52a94357051a0a8f8a3be9d8dafba18261ec1ff144d8fb52818bd35eb30exeArkeiStealer
2021-12-17 01:15:04f98e925c1ccab5e997e6e4e2349c4a31dcdfabebbf267d1bbf7943f35f0d4b57exeRedLineStealer
2021-12-16 23:08:03ee74cc4361dafb970087e89d502f3fa9dc073a4e31baaf9d1f843c630431bdbdexeArkeiStealer
2021-12-16 22:04:04158d30a43656ba2b6d7eec494fad8aa7ae861b0132f24065d2cc42d9396e0ef1exeRedLineStealer