URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.95.168.135
Firstseen:2020-05-29 10:37:36 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-05-29 10:37:37 45.95.168.135maxko-hosting.comNot listedAS211619 MAXKO- HUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-06-18 10:21:04http://45.95.168.135/zehir/z3hir.spcOfflineelf mirai ext zbetcheckin
2020-06-18 10:21:02http://45.95.168.135/zehir/z3hir.m68kOfflineelf mirai ext zbetcheckin
2020-06-18 10:17:22http://45.95.168.135/zehir/z3hir.arm6Offlineelf mirai ext zbetcheckin
2020-06-18 10:17:19http://45.95.168.135/zehir/z3hir.mpslOfflineelf mirai ext zbetcheckin
2020-06-18 10:17:17http://45.95.168.135/zehir/z3hir.arm5Offlineelf mirai ext zbetcheckin
2020-06-18 10:17:15http://45.95.168.135/zehir/z3hir.mipsOfflineelf zbetcheckin
2020-06-18 10:17:13http://45.95.168.135/zehir/z3hir.x86Offlineelf mirai ext zbetcheckin
2020-06-18 10:17:11http://45.95.168.135/zehir/z3hir.ppcOfflineelf mirai ext zbetcheckin
2020-06-18 10:13:03http://45.95.168.135/zehir/z3hir.sh4Offlineelf mirai ext zbetcheckin
2020-06-18 07:01:11http://45.95.168.135/zehir/z3hir.arm7Offlineelf tolisec
2020-06-18 07:01:04http://45.95.168.135/zehir/z3hir.armOfflineelf tolisec
2020-06-01 10:41:09http://45.95.168.135/SBIDIOT/yarnOfflineddos elf mirai ext Gandylyan1
2020-06-01 10:41:07http://45.95.168.135/SBIDIOT/rtkOfflineddos elf mirai ext Gandylyan1
2020-06-01 10:41:05http://45.95.168.135/SBIDIOT/zteOfflineddos elf mirai ext Gandylyan1
2020-06-01 10:41:04http://45.95.168.135/SBIDIOT/rootOfflineddos elf mirai ext Gandylyan1
2020-06-01 10:41:02http://45.95.168.135/SBIDIOT/mpslOfflineddos elf mirai ext Gandylyan1
2020-06-01 07:11:03http://45.95.168.135/SBIDIOT/x86Offlineelf 0xrb
2020-05-29 10:37:38http://45.95.168.135/SBIDIOT/arm7Offlineelf tolisec
2020-05-29 10:37:37http://45.95.168.135/SBIDIOT/armOfflineelf tolisec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-06-19 23:39:26cfb5627f8e4a4618d6073d228dffaae584238919fb350330c68a922629c1d7fcelf  
2020-06-19 23:39:268d5e263c28de6b7aa035cab8faafe41d68e6fc64ce0c52872b10866d8c590222elf  
2020-06-19 23:39:18c7392af2d1ed9187691cba02bda9c40083f2454819bef1091224704f092b167felf  
2020-06-19 23:39:17f9c48789815c8bae9a44368d21748b466a37059e629d5e0238891790826f5f01elf  
2020-06-19 23:39:16c7392af2d1ed9187691cba02bda9c40083f2454819bef1091224704f092b167felf  
2020-06-19 23:39:15c7392af2d1ed9187691cba02bda9c40083f2454819bef1091224704f092b167felf  
2020-06-19 23:39:14ae62d6414665e8cc9b07e47f2a352efdffca5d632437328b9f652a1245cfef21elf  
2020-06-19 23:39:13ae62d6414665e8cc9b07e47f2a352efdffca5d632437328b9f652a1245cfef21elf  
2020-06-18 10:21:04e39ba91284c27b2d0a21ae5853f09d00f760bf029d05fc937e524bbff35ad284elf  
2020-06-18 10:21:0217a988d2c4646f899aeb2cf21af505e38af6bc0709fc6a0574e68c72354a6f50elf  
2020-06-18 10:17:2209f64513cbef581cbae4d686934ff8bc1852cd5acf2f45a8ab5418dce0bdfe87elf  
2020-06-18 10:17:19497a9282625d766e8818431d0f3326d487f578f561e9475df3d5ceec8b27b684elf  
2020-06-18 10:17:1772bf53cfd38bc5cc1bd3787f94d41238546e56e7ea62b5ef6f7a8708a3db543celf  
2020-06-18 10:17:15de3fe1a9389ed607a443434b70a034573eee386ad26cd1a5880c038deafbce3aelf  
2020-06-18 10:17:13d7aad9b55d121d3385228994c6ea8b1efc69dbcedc3c45d13da47b33c80b7af1elf  
2020-06-18 10:17:11fa8041e313f5cea17fbf4bed47271afa1f4dbc0fc176183eb7558b4e7d51ff2eelf  
2020-06-18 10:13:03b4dad43056184322d986eefd08f2ad5f0914f5f45b40faacae8bb65db4109d5celf  
2020-06-18 07:01:111719cea7eb7b888f3350a7eb8797ff1e77beb044d324c820cead3f8d99fe773aelf  
2020-06-18 07:01:047a4fd879383e68aed494dc0dd72b64c33276ccd868a29b3019563c3951263345elf  
2020-06-01 10:41:090653bf441054913eafd471778a7036084916a6e27e5ad15b88d229897de8f5ffelf  
2020-06-01 10:41:0707caf6352cc22c407c21fd774decbbd6ccff0406b57c48833c305dece2f54e7belf  
2020-06-01 10:41:0507caf6352cc22c407c21fd774decbbd6ccff0406b57c48833c305dece2f54e7belf  
2020-06-01 10:41:040653bf441054913eafd471778a7036084916a6e27e5ad15b88d229897de8f5ffelf  
2020-06-01 10:41:02dfda624930ea2ad964f7f24522bf0a4e1fa97029e300160f8d73b82add277f1aelf  
2020-06-01 07:11:030653bf441054913eafd471778a7036084916a6e27e5ad15b88d229897de8f5ffelf  
2020-05-30 20:19:384a39435509938ef14ce7073463544f066bb1f19d478c3f3e27eede568e378ae5elf  
2020-05-30 20:19:370c57de4856dc2f21adb94bf3fb00eb279a448aedf9876b01dd22cfd1f8ab7576elf  
2020-05-29 19:33:548e2aedf7a486492a49254fdfb5e7e7f4a065f27cfb9ec822afd621ce8e799af5elf  
2020-05-29 19:33:4611c1ed7f4555f75bb4dd98cb4fe0f6c7e697ee2b30d3203dc74f69428456deaaelf