URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: glashandelperfect.nl
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-15 01:28:15 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-26 11:36:17 62.216.2.121da08.ams4.bizway.nlNot listedAS3265 XS4ALL-NL- NLno
2020-08-15 01:28:16 185.104.29.26web0089.zxcs.nlNot listedAS206281 AS-ZXCS- NLno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-15 01:28:16http://glashandelperfect.nl/ekryn/111u-59z-657024/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-15 10:00:02b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421adocHeodo
2020-08-15 09:28:038166f9d5647da264c416fb5151e8f329302965d5717c6d4210d146fc41acd16adocHeodo
2020-08-15 09:12:47e661e88652754e32269956878b435a3d8e7884d7af66fd23ec88f5ff1a59e235docHeodo
2020-08-15 08:53:14715b876221f1b5e1bcb052a019ee033638ba9829c8ee712edc2ef66cc27c0e7ddocHeodo
2020-08-15 08:31:0258b298e56c9f3ab83b11fd958ad8ca5a51fb8cbf2c6222c1d76f8e6d213bf2bedocHeodo
2020-08-15 07:44:13dae18dd9a3dbbfc06b5e5c10fc7dc93c670a0c191d7cb7065e9d478503274567docHeodo
2020-08-15 06:50:15f5c245a5f1123723691aaa790dca5d49533e18caaf9c0de3f8782404dda81d98docHeodo
2020-08-15 06:18:355028de3ce60c62f1e99fcc961491a81d8a3315f89afef5015243cf80d77872fddocHeodo
2020-08-15 05:55:1440f8be090c2e10a4175b11315d5adbd548b1a079fb450c6ff18b82b5ad0d75ccdocHeodo
2020-08-15 05:37:11f77afce2b8d4472fbcf09e30d3fddb8903ce48eebae03a294d7ca7819c07fdf5docHeodo
2020-08-15 05:03:546d849f43785ca5cf641082748de6d9fd4c8b5d11863de48acfff9ebe7ab20b32docHeodo
2020-08-15 04:48:320f66bd662c52e3cbc7af5fc1bf2b877c06965a6c276d4ff6ea2dd8aa22273d24docHeodo
2020-08-15 04:37:3294b9821024615e536b2196b18ad6a0c092e4030cc19a99f35d6cf7637a4a3eafdocHeodo
2020-08-15 04:05:25911f2bfa86abc00f8fc2ea9dfbe597349baff6522fff47de22aa0ae77f31ece9docHeodo
2020-08-15 03:35:165ef82a837959acd3ffd63fcfb6f497c2ed4b29c0f50047539044636365ba1d00docHeodo
2020-08-15 03:02:22b3b1d9de78d806f5d6869abbcf8eca4d70fc0167946479c7a173ac9729ef799edocHeodo
2020-08-15 02:35:157685045c26c2b57ea45d561d8f6b9d4746939825e90633a6e3d72480686c1858docHeodo
2020-08-15 01:28:16ec4f449e19e854e423694815adfbe603c3fac9326ca0c7e39245b4cbf009c9e8docHeodo