URLhaus Database

You are currently viewing the URLhaus database entry for http://45.205.1.59/ok which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3859834
URL: http://45.205.1.59/ok
URL Status:flame Online (spreading malware for 1 day, 12 hours, 36 minutes)
Host: 45.205.1.59
Date added:2026-06-06 17:06:21 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-06-06 17:07:11 UTC to abusepoc{at}afrinic[dot]net)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-08oksh 0452e5f363cfc17bf436564ac2cf30e71f7ee30d2d5d66768482c45f8a734d12n/aMirai
2026-06-07oksh 6b96b764b5051e1b4c319a8584ec401af75d33c0fa8d271c54e447e0a2e75a82n/a
2026-06-07oksh 1e9bddb6ecbfa47df9c31065029ee428f45f312f12afcef6875b8a92ce3c8612n/aMirai
2026-06-07oksh 87d48290bc7e22771784820398c55e4bd0153db4bfd4654c5b5aa482186c972cn/a
2026-06-07oksh 0136ff6bc34f3d104b3ae66ef3d11c01f9f964ba267fb1ed84a05cf117f02a35n/a
2026-06-07oksh 512c87314d027068df5d3faade026de695fd97a552a884479c2e184f8ba897f1n/a
2026-06-07oksh bd7525163c77b82056a0c285a02bf6a80de3c0b46958cf60d1d1a86b1207486dn/a
2026-06-07oksh 278e4f1ebc6ff4bbc02d48340fd6f576e69b14f0ae678c96b63fe3c7fd3b9b76n/aMirai
2026-06-06oksh fb940c752994f0e0989ff5e757d738954a6eaa5d71cff59a5063a0b1c4b64cd4n/a
2026-06-06oksh ad9f4e2c0ab954083fd8f92ca9b4e819ba2ea6c096fdd47e912ea6066592e724n/aMirai