URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.9.148.22
Firstseen:2025-11-20 14:44:05 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-20 14:44:08 45.9.148.22Not listedAS49447 NICEIT- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-20 14:44:09https://45.9.148.22:8443/test.htaOfflineopendir BlinkzSec
2025-11-20 14:44:09https://45.9.148.22:8443/apollo%284%29.htaOfflineopendir BlinkzSec
2025-11-20 14:44:08https://45.9.148.22:8443/shell.exeOfflinemeterpreter opendir BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-20 14:44:093715b37a8d14be2c63e57b34d805e61e89841a1cc03c9ccfd5e057e8726e7cb0hta 
2025-11-20 14:44:0906d443a444285a6d63de6286277008ac8154cfaed3a444f3ddc2a5e1df319333hta 
2025-11-20 14:44:07606f32714f9f26b59a0b7f5601e51335f394b899f35d7d0ab002b207cc7ad4b0exe Meterpreter