URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: legolan.nl
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-09-24 06:27:12 UTC
Total malware sites :1
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-04-27 19:38:43 188.114.96.3Not listedAS13335 CLOUDFLARENETn/ayes
2025-04-27 19:38:43 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ayes
2020-09-24 06:27:13 5.9.62.182rkoggel.nlNot listedAS24940 HETZNER-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-09-24 06:27:13https://legolan.nl/amazon/sites/gvocmsq95sa/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-09-25 01:06:438a73bdca97395b9f659104c200734008fe685faff6734fc31ce0cd575090f1b2docHeodo
2020-09-25 00:46:52e99def3b5bee603e6c7a2d91c61fa9fedb0ed8a7c0e8c7029e2c5d3bf70ba88fdocHeodo
2020-09-25 00:24:02af8ff28fb4ea041b8cbe3e93a2c9984e483b0fbda6945bc0172d0946d5c1cb7ddoc Heodo
2020-09-25 00:16:40ddca7bd9923ea1a93f054a8ea4c749b80793daf20550c9ee2f4e63446572c400docHeodo
2020-09-24 23:59:0189825271f1b18375f523320908826b553e9da21bce402e9844bd3d55446fb509docHeodo
2020-09-24 23:51:4830a0c59711e06c411f4e1a20c649f507a1ef69742192df4ede24d92289aee591docHeodo
2020-09-24 23:23:55fe2c4c0e8452ed6b2c6e644296e472af18a988e142404e89061f6cb8f2420593docHeodo
2020-09-24 23:16:098e4be7abeafb997210d1c39bf851ab0c4cd097268cf3664f53c72abc3dcce92fdocHeodo
2020-09-24 22:59:027b6806b4e83dde2a32e4d3f04439478a2a28eff8c723179a141152aa89c0c8fcdocHeodo
2020-09-24 22:33:3746996b6a7e3fb5f718730ed86bbfa6e57792d961db1bd60352e17703af38134edocHeodo
2020-09-24 22:15:187e1935fab86166df5d6770468bf12c57a50720c0b7ba90e21accf2ca8493ce15docHeodo
2020-09-24 21:57:08c4fc9ec7954c1bc71dc415464f2813e6151dd7c106526dfe3aa8d97ec3b8f9dedocHeodo
2020-09-24 21:36:09ff6440d9c01fb2fc8526c683c418271051ec21b1b730972f02ab6442bb0f83afdocHeodo
2020-09-24 21:19:242a3395e9459dc5f0fc72621c2299e98b4226e6b99cf6069d89004e3d430a219ddocHeodo
2020-09-24 20:51:44b638a54fb8b1ae9d64723adeea13dfada5ef1ad4d4c606ed9a34370f4d216d09docHeodo
2020-09-24 20:34:23a72430246d4ff63a287ccdb3d3eb1eea24af39ec67b6452658454f115f5a146cdocHeodo
2020-09-24 20:28:5749cb977b6bc82a34e7733da5b4a34862f85b5afd2c8a0691c79d9e2b86dca29edocHeodo
2020-09-24 19:58:1485c3fbc17a0daacdb938f7ea4b8dfa14ae9a099d59de1e9fef807b569c999acbdocHeodo
2020-09-24 19:37:419c92b09435e053ed7b07f0d33360b840b95e0bbd64092e06bf09020307e84b9adocHeodo
2020-09-24 19:14:38267834c0d23e344ce20d8814e0e5499c7f5bc32fbda08c9ebf721a3dcb2efe26docHeodo
2020-09-24 18:57:09b8c075d4057bdd225bd2328001ef2cc8efb5e79192d6c2fe8279677927714ec8docHeodo
2020-09-24 18:37:01df802c906676713581817048e135afe20200029ac5ff1c840ba82b5bbcda75cadocHeodo
2020-09-24 18:11:5032bbcef052b442f62a2fbb0c5dad498dcb779148f31f2e51d4f7a38245024f8edocHeodo
2020-09-24 18:04:0460b9c51a988490875a152231c3217de228b7406a1378ab07263aea7f02ecd3ccdocHeodo
2020-09-24 17:42:2537b5d86751a2c999901df382ddadc7aa72d891a4e24ef527e02266ffab2efa41docHeodo
2020-09-24 14:17:19460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974fedocHeodo
2020-09-24 13:48:55f1d7646cf6abe9a746a6dab251be541e66a294060a1f32665b7e1c5d54de17dcdocHeodo
2020-09-24 13:19:28bf6caeac64ebd3eca96f936635d26ea90e62f1093b72146a98a20623a13688cbdocHeodo
2020-09-24 13:03:0014d3028b892573f0d8b812deb455b13424beb8580cd1d928cabdbe4c613a7e22docHeodo
2020-09-24 12:29:31896f6e1b9eb9656cfc68db252241fc7087192661175a0604505742223f0ef016docHeodo
2020-09-24 11:48:05322437c9e679266325e5e5e4e5192b3480e02f680d56fbede6b807db9def583adocHeodo
2020-09-24 11:14:023094430b3d76d53847a19a95eb5729490be7efc8f68feb4b57aeb8fd72c94ee9docHeodo
2020-09-24 10:55:59c53bc4b67b9b49868bbb7d3a8323cbd2b411a41077e2b691eb9e66516dde0e4cdocHeodo
2020-09-24 10:06:3233412abe08dc8633c45ced70426d58498a93ec1ace826525f5fb495459709ac3docHeodo
2020-09-24 09:58:11ab91db60823e2094091fd21a60eda971c965e334da7b12f08b02334d781397e4docHeodo
2020-09-24 09:26:55cc6d1e1779c379b470c18ec2a37174c042c003b17425e7bddbd43876e7c8759ddocHeodo
2020-09-24 08:35:29573cf8b0e537a825c17e7f74be98dc2516d0b509eb22cc7a259717e53d50ec53docHeodo
2020-09-24 08:26:25e4a782671d6a001f226fd064f2f6204cb368f6e4e82aad502a4d5cd56b65a78bdocHeodo
2020-09-24 07:53:056e5bcd9db826f2b855f63e8a591e02ebb0bbd141387d2922e3e251fc8ddbcbb8docHeodo
2020-09-24 07:28:476cbd2115091ed6aac27b36f75ef0aa1328e9cd43fc463b039ff9cefed0d8b1f8docHeodo
2020-09-24 06:50:0054d6881837b3fcb6a0b3e639c58f6e159abb745d0862e1f5cabe6c7df3a3da12docHeodo
2020-09-24 06:27:138b209e2d294b8c5b50bd83d9fd9184268ce21313f7d5876d74c7e10f48ac946edocHeodo