URLhaus Database

You are currently viewing the URLhaus database entry for http://45.141.233.85/po.js which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3562562
URL: http://45.141.233.85/po.js
URL Status:Offline
Host: 45.141.233.85
Date added:2025-06-16 15:02:14 UTC
Last online:2025-06-25 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-06-16 15:03:12 UTC to abuse{at}virtualine[dot]org)
Takedown time:9 days, 0 hours, 53 minutes Bad (down since 2025-06-25 15:56:25 UTC)
Tags:ascii js strrat link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-25po.jsjs c8c8958a70c21a784658ed3fe04e92aa0fe762f8ddbff9a41da4bc54bb7b1d9cn/aSTRRAT
2025-06-19po.jsjs 7e991abf1d9790847acb2d3d249077998465dfff256ede970fca79766b92aaa1n/aSTRRAT
2025-06-16po.jsjs ac7c8ca96a634062da1e6c36417b96f674dfd233c2b86b10b1969357c02bcd5bn/aSTRRAT