URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.170.245.23
Firstseen:2025-08-27 07:41:04 UTC
Total malware sites :25
Online malware sites :0 (0%)
Offline Malware sites :25 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-27 07:41:27 45.170.245.23Not listedAS28423 Truxgo_S._de_R.L_de_C.V- MXyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-09-07 13:30:25http://45.170.245.23/a-r.m-4.SakuraOfflineelf gafgyt ext ua-wget abuse_ch
2025-09-07 13:30:18http://45.170.245.23/m-p.s-l.SakuraOfflineelf gafgyt ext ua-wget abuse_ch
2025-09-07 07:47:21http://45.170.245.23/i-5.8-6.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-09-06 19:45:14http://45.170.245.23/Sakura.shOfflinecensys gafgyt ext sh ua-wget NDA0E
2025-09-04 17:47:13http://45.170.245.23/a-r.m-6.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-09-04 12:10:23http://45.170.245.23/a-r.m-5.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-09-04 12:10:20http://45.170.245.23/m-i.p-s.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-09-04 12:10:20http://45.170.245.23/s-h.4-.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-08-31 01:45:33http://45.170.245.23/p-p.c-.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-08-31 01:45:33http://45.170.245.23/m-6.8-k.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-08-31 01:45:33http://45.170.245.23/a-r.m-7.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-08-31 01:45:31http://45.170.245.23/x-3.2-.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-08-31 01:45:31http://45.170.245.23/x-8.6-.SakuraOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-08-27 13:18:14http://45.170.245.23/hiddenbin/boatnet.arm7Offlineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:35http://45.170.245.23/hiddenbin/boatnet.x86Offlineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:35http://45.170.245.23/hiddenbin/boatnet.mpslOfflineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:32http://45.170.245.23/hiddenbin/boatnet.ppcOfflineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:31http://45.170.245.23/hiddenbin/boatnet.sh4Offlineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:28http://45.170.245.23/hiddenbin/boatnet.arcOfflineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:27http://45.170.245.23/hiddenbin/boatnet.armOfflineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:27http://45.170.245.23/hiddenbin/boatnet.mipsOfflineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:27http://45.170.245.23/hiddenbin/boatnet.arm6Offlineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:27http://45.170.245.23/hiddenbin/boatnet.spcOfflineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:27http://45.170.245.23/hiddenbin/boatnet.m68kOfflineelf mirai ext ua-wget ClearlyNotB
2025-08-27 07:41:27http://45.170.245.23/hiddenbin/boatnet.arm5Offlineelf mirai ext ua-wget ClearlyNotB

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-09-07 13:30:2560efa56c6afd73e1cae8a7a9986ed4f03f0f0a17317eb9b0c354763fffaad0beelfGafgyt
2025-09-07 13:30:1868641d8a30aab4113cd52f6b55ca7d80e2e46227c034912647bc448cbd1a0530elfGafgyt
2025-09-07 07:47:21288c0cf5ca444faccb9643278a77c6f89577cb7bcd87bc27c006822af47494beelfGafgyt
2025-09-06 19:45:14f1880667151a13eb689e5c1b2318b3c8ecce80315b40c4f89f30bcdc8c680bfashGafgyt
2025-09-04 17:47:13d656cb948d29b282e895536ada6ef7432617ec2e3da7fe1a44f91b075b8a348belfGafgyt
2025-09-04 12:10:23aafde5a93ad631683791e7d2af5bc1ece72c0c3c5ba05ceab75170173d7c2f8eelfGafgyt
2025-09-04 12:10:20b41a141a47a814a7bd994e912fc03bdf5fa79305902443c346f805b563575bccelfGafgyt
2025-09-04 12:10:2011c5dc3af21d70bbd180585286cc6c575b13531982647d0818ab8789f70b70b7elfGafgyt
2025-08-31 01:45:3360efa56c6afd73e1cae8a7a9986ed4f03f0f0a17317eb9b0c354763fffaad0beelfGafgyt
2025-08-31 01:45:33d1cff4d398e38e17c0e368628436107a03aa1f345da354181104687e26313168elfGafgyt
2025-08-31 01:45:3367cd9ade9860af165de29dc08bd70af13b7888eed85ffa43c35df2fcf4a9d473elfGafgyt
2025-08-31 01:45:31edaffffc4170552035f1c299b8cca11e8ddac1d45b120dd69ad8195b01d7f1d8elfGafgyt
2025-08-31 01:45:31ea34bcef8faf9279994a6ae4b99e7ac3e3a3d9af8973e5162f979b33a206a0f3elfGafgyt
2025-08-27 13:18:1457ddf7a273a8d2ffa4dce02849fa00ea6e020d5bb7613e557028bacaaeb9eebeelfMirai
2025-08-27 07:41:35b0d300699cdd6714233c2fd583a3862b1fd504331274f5be0554e69f676b0931elfMirai
2025-08-27 07:41:35445d46eecca198c0a54b890fe61667988cf7d3c871e3dee10aa4091d0315fe22elfMirai
2025-08-27 07:41:32710de14df1755991077f7c4012654f5f08e1197d62feea551e085f94684596a1elfMirai
2025-08-27 07:41:31a56b5e6a218bea2499e3c50546d46d28468c487884d15a4751f46b418bf71603elfMirai
2025-08-27 07:41:28940715b91161c525383280e0f4450acdb367830a3d118c3eb50cb3c04b065bd9elfMirai
2025-08-27 07:41:271a71c0476d439944840c4757bbc8941ca3c8a768c460fa7a6eb8272597e46d53elfMirai
2025-08-27 07:41:2610345219683f1556052bae980f0950b9e2325dea50ea08fa3e254cbb318b61edelfMirai
2025-08-27 07:41:2630dd3eeca0d04dca759f06854a1e74a6ae3d7445c08246492ed3eaa97391992eelfMirai
2025-08-27 07:41:26c38787690fabcae5453e0161aa8a07d0e0db2211426456c2cb33d5f22f1651eeelfMirai
2025-08-27 07:41:268111e07ca14812e7ae8e7a7b3bb8a236b3169b4b3b6d0b0c49f6c5da835b0cfdelfMirai
2025-08-27 07:41:26c71ee5c7e0a1e3f69829a41d38422c340a87429e9c987775f569782c62476ad2elfMirai