URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: ethdesign.nl
Domain registrar:team.blue -
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-03-29 15:40:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-03-29 15:40:05 185.94.230.123www64.totaalholding.nlNot listedAS48635 CLDIN-NL- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-03-29 15:40:05http://ethdesign.nl/cgi-bin/fdKJUUr0V26Z8PPzwpP...Offlineemotet ext epoch4 redir-doc xls Cryptolaemus1
2022-03-29 15:40:05http://ethdesign.nl/cgi-bin/fdKJUUr0V26Z8PPzwpP...Offlinedoc emotet ext epoch4 heodo ext SilentBuilder Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-03-30 09:54:055c5982e66d129ffc81e2afdc277b205739de990caaa2fa12443b155bb16d7ef1xls SilentBuilder
2022-03-30 09:05:165e42f72b6f48384d2369d13cce199bc20da44c757705ba69765152d0d1d02f96xls SilentBuilder
2022-03-30 08:01:58c56d2d89a7b4e8e3be75d64d8e926afa91d8fc7c9cdbf50933d3b079c58423d5xls SilentBuilder
2022-03-30 06:50:14bf4c74c969381aacc9d55ff9a4062b33639ff53eed6c07534bf83cf990a83353xls SilentBuilder
2022-03-30 05:57:017bc0a080f39d5c19c14ef549d30373cf03116dd942536ee0c02249e4f94fafbexls SilentBuilder
2022-03-30 05:37:58bfe23f7a26dafe38fd6799a726ed7aa7856fb88f5892841e58b06a93caf118e8xls SilentBuilder
2022-03-30 04:41:221b3dcc87c329e9a704c55890eced55298a7fe31f93de0dcbf15924aa87d4b3afxls SilentBuilder
2022-03-30 04:04:014c775dc66dd1e7eefeb86433444c9bbc877514e792cb453c194199333d0aba86xls SilentBuilder
2022-03-30 02:41:08b2384667cf5b1834ef6f3173c72953dd0544b2c49e5ec5b0075629a89e572132xls SilentBuilder
2022-03-30 02:08:469e567a344081987a4426f78ec523045fd89cefc8790ccd11bc7c7e84a0816144xls SilentBuilder
2022-03-30 00:57:539b7452e408963921f685e25246f5c63af11c407ac04a6fa47ffe38b3325b52bdxls Heodo
2022-03-30 00:14:353f55a18289a4defdb2b50e5314a7972d39bd0d4e7e2da0826a91f163eebe2a9cxls SilentBuilder
2022-03-29 23:58:48fe7634683727f4e2c4ddaf2eea56dd2291955ef5396c96bb353ccbc080e996d7xls SilentBuilder
2022-03-29 22:48:59ef3bcb266ee4c7a41d149583984bbf42d469da86d9537dfdf3565d0388d80f38xls SilentBuilder
2022-03-29 22:38:0744fbb7ebee68799512eae11164cfce84ba5836fa6a3674df33e9e527a6edfb01xls Heodo
2022-03-29 21:18:02ed2f8d7e4690bad774218068fb147924da6ac0dc68f5329699e01075b866a262xls SilentBuilder
2022-03-29 20:43:09bbc1337630f46853905e7fa804eb8bf2b3644f3a16a1911ea1fbd7fe1811c1ecxlsSilentBuilder
2022-03-29 20:31:3830c386f8b27cab9ed4525f9123ace697473b0a9c1a5d17ce0267258535926383xls SilentBuilder
2022-03-29 20:03:4907610eca3a554bbc3279af58afb13d4da4234771cc60b020fac93605a9a8a429xls SilentBuilder
2022-03-29 19:23:26b8815fc4a5adf0e8d11f79313180c3c444b056d9cceda1e151bd29a2dbd4b312xls SilentBuilder
2022-03-29 18:32:22299eef9367c7d46794f985f1653108dff2ea664d29f31b8ba1a08c934e1d42b6xls SilentBuilder
2022-03-29 17:53:56de0451fa84d12094775843b0424bfcc18832943128c01ba088acae9c80a402e3xls SilentBuilder
2022-03-29 17:14:574268dc47de4d11bc5cc3876e399602c2904c5903a08e1150763c0534a38a1ffaxls SilentBuilder
2022-03-29 16:20:372f3f7c6de82942afe012bc20ff8122859b1dcae1fc267f1fdd03fb2ea7605f9axls Heodo
2022-03-29 15:40:0406e6cca9f0d223c50059e62e950d32b5e84d94d951cc4bafe863e3acd52c38cbhtml  
2022-03-29 15:40:040fdc9504c43e5829e5b84c12826b43e362787fc2446c527ebd3b373dce12c86axls SilentBuilder