URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.43.36.223
Firstseen:2024-12-16 17:18:04 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-12-16 17:18:07 45.43.36.223Not listedAS135377 UCLOUD-HK-AS-AP- TWyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-01-09 12:50:08http://45.43.36.223/x864433.elfOfflinebackdoor elf GetShell Joker
2025-01-03 17:16:08http://45.43.36.223/hr.exeOfflineexe BlinkzSec
2025-01-03 12:43:19http://45.43.36.223/m/mode11_N1Fz.exeOfflineCobaltStrike ext malware opendir trojan Joker
2025-01-03 12:43:19http://45.43.36.223/m/mode11_AKUh.exeOfflineCobaltStrike ext malware opendir trojan Joker
2025-01-03 12:43:19http://45.43.36.223/m/mode11_CBNx.exeOfflinemalware opendir trojan Joker
2025-01-03 12:43:19http://45.43.36.223/m/mode11_0HVJ.exeOfflineCobaltStrike ext malware opendir trojan Joker
2025-01-03 12:43:19http://45.43.36.223/m/mode11_UVo6.exeOfflineCobaltStrike ext malware opendir trojan Joker
2025-01-03 12:43:14http://45.43.36.223/m/mode11_6dMu.exeOfflinemalware opendir trojan Joker
2025-01-03 12:43:14http://45.43.36.223/aarch643308.elfOfflinemalware meterpreter opendir Joker
2025-01-03 12:43:13http://45.43.36.223/m/mode11_qLf2.exeOfflineCobaltStrike ext malware opendir trojan Joker
2025-01-03 12:43:11http://45.43.36.223/m/mode11_buqd.exeOfflineCobaltStrike ext malware opendir trojan Joker
2025-01-03 12:43:10http://45.43.36.223/m4455Offlinemalware meterpreter opendir Joker
2025-01-03 12:43:09http://45.43.36.223/45678.elfOfflinemalware meterpreter opendir Joker
2025-01-03 12:43:05http://45.43.36.223/arm3307OfflineGetShell malware meterpreter opendir Joker
2025-01-03 12:43:05http://45.43.36.223/5544x64.elfOfflineConnectBack malware meterpreter opendir Joker
2024-12-16 17:18:08http://45.43.36.223/mOfflinemalware meterpreter opendir Joker
2024-12-16 17:18:08http://45.43.36.223/svchostinter.exeOfflineCobaltStrike ext malware opendir Joker
2024-12-16 17:18:07http://45.43.36.223/3344.binOfflinemalware meterpreter opendir Joker
2024-12-16 17:18:07http://45.43.36.223/3344.exeOfflinemalware Metasploit opendir Joker

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-01-09 12:50:08198a0922f19f098abb5800a89f581aab8021e74d7b824156a3027b7f3c0e7048elfGetShell
2025-01-03 17:16:085e6358f4f3996d0431d1d4aaae4dc1bb2d90d9a160ec9e1ff106b9e97f2cde60exe 
2025-01-03 12:43:19d49c2451497109ae9f2646d06aa6dcf51b0f6af825d07f516b8dd59c03602401exeCobaltStrike
2025-01-03 12:43:19899c529454c4286185a9d3c039277ce28957590e7ed3e586ccf1487317159c22exeCobaltStrike
2025-01-03 12:43:19f94f93b481fe7819ff46614f0025eb661bb863b9579958c3b408fdf941ad2efcexe 
2025-01-03 12:43:193625fddc2687c086d6d4a4300b03d4a2492acf8e843697f57830bb40956f495aexeCobaltStrike
2025-01-03 12:43:19ef1967d9e33cbed9f12a504bdc642c9c12cfbac79a4421617f32e1aa2dc82c6fexeCobaltStrike
2025-01-03 12:43:14cf2079cf272342785f58c393d5013ec99184324549f93c144f79564d106d5e98exe 
2025-01-03 12:43:13e1b6bd9876ca534e99b28403661e09b7a1ab7dac706df3962a0c975ba5b9e8ecexeCobaltStrike
2025-01-03 12:43:134b382d5cd06a3d6d2cb8448927a465c1202f45441b9b2403005c47509c79e768elfMeterpreter
2025-01-03 12:43:114a3341b1a681826f08bc9ec90ca24459826bb28f909030ba522d5ae2c92467d7exeCobaltStrike
2025-01-03 12:43:10314ff804868ba165d60ca94b2cc6b161cc35f52cd1022b2e9533ea7dded93bd8elfMeterpreter
2025-01-03 12:43:08dd8aa084083b7c1dc1596cc89f295a90db24edb261e83eee41087f5650136d4felfMeterpreter
2025-01-03 12:43:058eda77699f86b79b873127b642556f88e0ca7a84c5b45d6a98a6cd5a612ff24delfGetShell
2025-01-03 12:43:05561b89228b562c0a0b53b5848a179fac10ae0226706db82e8dd24226da199d94elfConnectBack
2024-12-16 17:18:08314ff804868ba165d60ca94b2cc6b161cc35f52cd1022b2e9533ea7dded93bd8elfMeterpreter
2024-12-16 17:18:08c30fc17df989f401a1518088a58bef58c6e0ee7b91960452a547c87af9cda957exeCobaltStrike
2024-12-16 17:18:07a908193949c9b3f45f3b409d4b28949014ae27e9bb1e962fd5e65ebbc97fb89eexeMetasploit
2024-12-16 17:18:06563955d55235b615fcf6434cede40f00a358c3af25f2419c66152b674af9f338unknownMeterpreter