URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 45.95.55.24
Firstseen:2022-04-15 06:12:02 UTC
Total malware sites :12
Online malware sites :0 (0%)
Offline Malware sites :12 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-04-15 06:12:11 45.95.55.24flyhosting.deNot listedAS12586 ASGHOSTNET- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-04-18 05:42:03http://45.95.55.24/wget.shOffline bjornruberg
2022-04-16 21:42:03http://45.95.55.24/bins/meow.sh4Offline32 elf renesas Tsunami ext zbetcheckin
2022-04-16 21:41:03http://45.95.55.24/bins/meow.arm5Offline32 arm elf Tsunami ext zbetcheckin
2022-04-16 21:31:03http://45.95.55.24/bins/meow.mpslOffline32 elf mips Tsunami ext zbetcheckin
2022-04-16 21:31:03http://45.95.55.24/bins/meow.arm6Offline32 arm elf Tsunami ext zbetcheckin
2022-04-16 21:31:03http://45.95.55.24/bins/meow.mipsOffline32 elf mips Tsunami ext zbetcheckin
2022-04-16 21:31:03http://45.95.55.24/bins/meow.m68kOffline32 elf motorola Tsunami ext zbetcheckin
2022-04-16 21:31:03http://45.95.55.24/bins/meow.spcOffline32 elf sparc Tsunami ext zbetcheckin
2022-04-16 21:30:04http://45.95.55.24/bins/meow.ppcOffline32 elf PowerPC Tsunami ext zbetcheckin
2022-04-16 11:42:04http://45.95.55.24/bins/meow.x86OfflineDDoS Bot elf mirai ext Tsunami ext Gandylyan1
2022-04-15 06:12:11http://45.95.55.24/bins/meow.arm7Offlineelf tolisec
2022-04-15 06:12:11http://45.95.55.24/bins/meow.armOfflineelf tolisec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-04-18 05:42:036ad155e8d3ff8c11b94fc2d169006642c4517bedfe3adcab3c56e13aec7821abunknown 
2022-04-17 04:03:04319edd025e8ed8ec6012c43d813250c205abb209b9b2e073c9d80f25ec9c5cabelf  
2022-04-16 21:42:0315082619f1f2fc0d34de15cf4da69f0f9f33d9c9820d4a53d5bfce9b7c8deec1elfTsunami
2022-04-16 21:41:03b5ae6ed97d31d6d4ea51aad337f2d0952568a5613190e3e8f9f5fa330bcb744aelfTsunami
2022-04-16 21:31:031e5c55437e316570ee7939d5bcc4898182e0e25c2d5a9816e1be830146bb5ddaelfTsunami
2022-04-16 21:31:03aff5f787b839f6c0354b2041d3f499857e20011b67bb9499aec5351d42060b47elfTsunami
2022-04-16 21:31:0373317bc871806a38225a378292a9597f1ef14116ebdf6f4cc18105e9061c85c9elfTsunami
2022-04-16 21:31:03af4ec309bbf6f3ab2c41f2558518ca279bd29be453fbc8787370c8047e456678elfTsunami
2022-04-16 21:31:0306049a837635c0f02150578a9f8067d3d06344d96d95c8b2374983385d85833delfTsunami
2022-04-16 21:30:04fef2be041a81f930df8f01d0470cac7c94f104ddda72bc60ddf90d4d85288f77elfTsunami
2022-04-16 15:13:19314bf0b322bf1bc763cb5a7540585af6244b04ba7e58aef1776002aa93618b9aelf  
2022-04-16 13:53:48cfc37f73db3dba90f974c0a8f0308dd1f51235aea4335b2f346ecf0503365613elf  
2022-04-16 11:42:041917aa3e5bfd1c6a958ca61875c4f58edcbf68d5b954707523b3088fbb096363elfTsunami
2022-04-15 06:12:116ff0921e19875d03f37f8a8e1067dea3b6b1f83332beadb6607d9b365b20df7belf  
2022-04-15 06:12:119ed015931740f36f3e5d987490e1e93f8cb6a5fedce9e0f965ec06d41114f820elf