URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.amd-net.de
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-27 21:34:33 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-29 23:56:49 146.0.35.70epycserver.ctr-dragonmail.deNot listedAS24961 MYLOC-AS- DEyes
2020-08-27 21:34:34 213.202.225.111srv1438.dedi.server-hosting.expertNot listedAS24961 MYLOC-AS- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-27 21:34:34http://www.amd-net.de/wp-content/ET19REN/Offlinedoc emotet ext epoch2 heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-28 11:35:46c7581272b851d63a9011c85fcd578559957a89b22b58e0b933f38236c442c8a0docHeodo
2020-08-28 07:49:19f35f09ee31dc9ba4c3d871882fadeeb10ed716f5a87be56e6129b111b6e5e34adocHeodo
2020-08-28 07:25:418658e7ea7f3c4c680d6ddeecf93b59b9bfd3298d79d6f0e7a5c3d9aa1623d961docHeodo
2020-08-28 07:01:4488050d35083b23cbad8c80519f05c4c66eac22c93834338cbe483737e6b2951cdocHeodo
2020-08-28 06:37:522507d621fe85fc30dc544957a545cbf5ce274ab84800ad014786c512d4a988a9docHeodo
2020-08-28 06:07:00d08315a0a97b0c8716273b13bc52e85c717f2f90d04b0b1dbe88b33e08d90d66docHeodo
2020-08-28 05:49:14642f0b1333a6ccce34906af2c3332ee52c9580f7b91ce7e4fb658e0915b43e73docHeodo
2020-08-28 05:28:11719703764819a3ae83679118e6bb21f6978fc85b753b794d004f4f45cab344d0docHeodo
2020-08-28 04:00:18d15d207c796247cb72e865fb89b2d86126c3ae9e3f7f84d6d799a5c179fee17fdocHeodo
2020-08-28 02:25:35ea1ce5f9d12c67465b28319cf9b23a41cf938fe17878362a3a58f68bd85a9703docHeodo
2020-08-28 02:07:478924cd43cae04cf71c93149b8d2a6729ae28edc120bff304e833416121085341docHeodo
2020-08-28 01:45:41bc91d23ce538ccd2b6c67c96f1bf75feaef826eb23f47dfab14649052bbd3165docHeodo
2020-08-28 01:25:02e6edc4b1f9c852d2f31179fa566f367f0fb60ab7637e50e54140302337c113f2docHeodo
2020-08-27 23:53:55849e307244b485130d232a6fc0ff55cb46da7d823229add05f38b37b74139dbcdocHeodo
2020-08-27 23:38:55756e4923d304155c0d36eb181301ce7da659c88df63d09d7a57ace593ebf2ffcdocHeodo
2020-08-27 23:22:545ea25ce6387f4fc4d741273dda0eefc709a68ab1fe384cffee188f091a2945fcdocHeodo
2020-08-27 23:06:406e90df31ca22290bcfbe1534826b71d5f71962a9c1841911be1bfae3fc033d39docHeodo
2020-08-27 22:54:558f33d7ea4a7ba61871627527e0d0ca62bf82f56d8a40448ced4087f3654fd8dedocHeodo
2020-08-27 22:53:04fc2c979f533e79f45f858febf1103743fc092cc5882960c399a2d7764a067fc1docHeodo
2020-08-27 21:34:34eaec53953f36479ef2776996838d45e6dd7a98b8dde7f3eb8677a25c1f0aff4edocHeodo