URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gtdesign.ch
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2018-05-17 15:33:00 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2018-05-17 15:33:20 185.117.169.151server29.hostfactory.chNot listedAS200713 FREY-AS- CHyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-07-29 14:16:05https://gtdesign.ch/cut_r_37ul9/payment/i9k97o/Offlinedoc emotet ext epoch2 heodo ext spamhaus
2018-05-25 15:55:10http://gtdesign.ch/oFNj7EV/Offlineexe heodo ext oppimaniac
2018-05-17 15:33:20http://gtdesign.ch/lexhandel/4hbVs2/Offlineemotet ext heodo ext JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-07-30 11:11:3718190f715f0c05ac6e28e0fa78c58fe7a1f6a0733be72ea6494e4340611c2194docHeodo
2020-07-30 09:32:56839a966436672446a68fede0e400e5e124c90bae0e6166de896bcc790899a376docHeodo
2020-07-30 09:00:23f69221bcda2041011a5346b30da22aac2af5ed52c961455f6529339faa519dbcdoc Heodo
2020-07-30 08:41:37ede4d3f3f62948285291afc16d31abd1c17c5f9db3ceb0e376151913977749cedocHeodo
2020-07-30 08:28:3544e198d158e76b7f97f737aa5b74de20f159ad7f13b41608d7ef9b793201cb62docHeodo
2020-07-30 08:09:47fd2c870bab01edcb6af885cc070a9ededf595bb1b3613b83fb9313a3caf5e014doc Heodo
2020-07-30 06:39:3447c48111a87bb2eaa02eeea65c8d80648d437d73124be5135ae75b968b0ee41adoc Heodo
2020-07-30 00:49:03babf9bbe00be892ecb7b1d8774cc33a3bae77c5b3d414f640c3f136365acea11doc Heodo
2020-07-30 00:38:32bc06aea71e46ed5e64ca7cf24f3b794f46b9371d1df13696a3dfe4096a3bb6acdoc Heodo
2020-07-30 00:32:007b459b39196f8a02d1d76081fd57227679c791e3cefa667a2264e36cb79230aadoc Heodo
2020-07-29 23:30:330bb41da3d7f6f972f06276bd500f8c8c520928871f48a3751835a23497658939doc Heodo
2020-07-29 23:16:59247650d657b93cdc868b938cf09c549175ede9f04050b49bf731bf4187040030doc Heodo
2020-07-29 21:45:10ea1d07ae55467195b610358c91f9d4cb4f280d055e9a86158339ca3bdba8ca15docHeodo
2020-07-29 19:27:14018beffb57923eb38dac054bea5fce0c4e9aca87f1971e226c7a7bacad5606b7doc Heodo
2020-07-29 16:36:25de8f1977525fb3ecc4525e54abda09a1e03d7adeaa92d60616d631ebc3bf604adoc Heodo
2020-07-29 15:38:459e9bcedb989bda32fb610816c436af0667eb5c22bb6a3d20fb4bd426dbee88addoc Heodo
2020-07-29 15:21:07d92e4dd34381a1b20f114dc122c6f542aebe6d7633579c8b6f1d934f25666201doc Heodo
2020-07-29 15:04:570cbadb841dc2c7d6152c653d711cd5ac8ca759142231e728789ff256b2d9a7e4docHeodo
2020-07-29 14:50:369c24d6fd85470958aea67d26f6293c5d8cb091ccac7299fcc6c243ff90382cbedoc Heodo
2020-07-29 14:35:33d32b9efd8f82427e98069b5a06bcde907a9f906406d27e85ff7741cc7d338febdoc Heodo
2020-07-29 14:21:443681daa87fcd7273080d8c9943be0e8f549075f23e2ceef7e89875649ad5a0efdocHeodo
2020-07-29 14:16:053c74f7013284b63dde1a5ab03d7b238ca960e7be7847fe31b343b04030d1c029doc Heodo