URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.94.31.127
Firstseen:2025-10-02 05:34:05 UTC
Total malware sites :31
Online malware sites :0 (0%)
Offline Malware sites :31 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-02 05:34:10 45.94.31.12745.94.31.127.powered.by.goldSBL687507AS210558 services-1337-gmbh- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-10-07 05:41:23http://45.94.31.127/MyFuckingBins/mipselOfflineelf ua-wget abuse_ch
2025-10-07 05:41:23http://45.94.31.127/MyFuckingBins/arcOfflineelf ua-wget abuse_ch
2025-10-07 05:41:23http://45.94.31.127/MyFuckingBins/i586Offlineelf ua-wget abuse_ch
2025-10-07 05:41:22http://45.94.31.127/MyFuckingBins/i686Offlineelf ua-wget abuse_ch
2025-10-07 05:41:22http://45.94.31.127/MyFuckingBins/mipsOfflineelf ua-wget abuse_ch
2025-10-07 05:41:21http://45.94.31.127/MyFuckingBins/sh4Offlineelf ua-wget abuse_ch
2025-10-07 05:41:21http://45.94.31.127/MyFuckingBins/arm7Offlineelf ua-wget abuse_ch
2025-10-07 05:41:21http://45.94.31.127/MyFuckingBins/sparcOfflineelf ua-wget abuse_ch
2025-10-07 05:41:21http://45.94.31.127/MyFuckingBins/armOfflineelf ua-wget abuse_ch
2025-10-07 05:41:20http://45.94.31.127/MyFuckingBins/arm6Offlineelf ua-wget abuse_ch
2025-10-07 05:41:20http://45.94.31.127/MyFuckingBins/x86_64Offlineelf ua-wget abuse_ch
2025-10-07 05:41:20http://45.94.31.127/MyFuckingBins/arm5Offlineelf ua-wget abuse_ch
2025-10-06 19:01:14http://45.94.31.127/w.shOfflinemirai ext opendir DaveLikesMalwre
2025-10-06 19:01:14http://45.94.31.127/c.shOfflinemirai ext opendir DaveLikesMalwre
2025-10-02 06:00:17http://45.94.31.127/MyFuckingBins/Labello.i468Offlineelf ua-wget abuse_ch
2025-10-02 05:35:26http://45.94.31.127/MyFuckingBins/Labello.x86Offlineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-10-02 05:35:23http://45.94.31.127/MyFuckingBins/Labello.sh4Offlineelf geofenced mirai ext opendir SuperH ua-wget USA botnetkiller
2025-10-02 05:35:23http://45.94.31.127/MyFuckingBins/Labello.m68kOfflineelf geofenced m68k mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:35:22http://45.94.31.127/MyFuckingBins/Labello.mpslOfflineelf geofenced mips mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:35:22http://45.94.31.127/MyFuckingBins/Labello.ppcOfflineelf geofenced mirai ext opendir PowerPC ua-wget USA botnetkiller
2025-10-02 05:35:22http://45.94.31.127/MyFuckingBins/Labello.spcOfflineelf geofenced mirai ext opendir sparc ua-wget USA botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/debugOfflineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.mipsOfflineelf geofenced mips mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.x86_64Offlineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.arm6Offlinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.armOfflinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.arcOfflinearc elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.i686Offlineelf geofenced mirai ext opendir ua-wget USA x86 botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.arm5Offlinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:34:10http://45.94.31.127/MyFuckingBins/Labello.arm7Offlinearm elf geofenced mirai ext opendir ua-wget USA botnetkiller
2025-10-02 05:34:10http://45.94.31.127/1.shOfflinegeofenced mirai ext opendir sh ua-wget USA botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-10-06 19:01:14b5fa8d608a12f3218afec958883be6efbf33e37861cd4102b60d11fd4f0585c9shMirai
2025-10-06 19:01:1373c583e1b00f76358b77f3c42231b13180e55d25e0e85f7283c501a8d1994c23shMirai
2025-10-02 05:35:26ccc6687d55dfeadf98b084e5793ea4d701bbaba59a7486532b1f548f6360112belfMirai
2025-10-02 05:35:23ef33efbfbe671d27b31f2df01219e68f2e3bfcd66956a9fd8b9a8151a9b75d50elfMirai
2025-10-02 05:35:22934fe47ae1664567345559c342eba464aa377c1bdd50d728ba070f9343c7fc30elfMirai
2025-10-02 05:35:223710c2270c07a02df0c2a8e2582b2142ca5384d7cf102474bedd9137b00362d1elfMirai
2025-10-02 05:35:22d4372744acf13969afac12150781b853ebd19f0a01447816763fe3949e351b74elfMirai
2025-10-02 05:35:223850533162a9a2790f751d0ffdec398b8329237663bf5463ecf9f695d09a7c7celfMirai
2025-10-02 05:34:10e5418d13a80d3d12aa6defc35ee83d93548730d86ff298739a33b2e5be0a2356elfMirai
2025-10-02 05:34:10cc1ce387d6dbdf3eb5981207351fe584d9f33fa04425b7c907e36acedca925f7elfMirai
2025-10-02 05:34:10181772d1375e7c40c29e78937c2d8baa04810db808adf2814a4295e60810efaaelfMirai
2025-10-02 05:34:109db960ba3c7049755dba3ad900f4f4709795cc090cf1ed2e6be1cfb1db713edeelfMirai
2025-10-02 05:34:10c8295c8b5be86dbda4da6c0df624eeb7190ef156e5a3b6264923d02a53d7a3c2elfMirai
2025-10-02 05:34:1036f916270f34cdf9dca6eca1839f453dbc72ec09c5e5b183e0f2be662b901cf0elfMirai
2025-10-02 05:34:105d125863cda9a3413fb4fafb9663b9f7af06d2df1e403939b424aeed7f7fe3acelfMirai
2025-10-02 05:34:1087b2e84ad84e8bc204b6be5483d78855af000e999f0b63c47c86566963c55dccelfMirai
2025-10-02 05:34:1098177fbf9d8537b709dd37dbc170f97085bd809fc400298fee0dd8f489375cd9elfMirai
2025-10-02 05:34:1090f334965ba865614e629c4b6b02aeee9aa40adc45f81f5e80b0f1fcf2f674b6shMirai