URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: www.dembeck.de
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-13 11:45:06 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-13 11:45:07 84.19.26.112server12.tldhost.deNot listedAS30962 COMTRANCE-AS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-19 20:51:07http://www.dembeck.de/img/sites/8vvpttt/g0y2823...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2020-08-13 11:45:07http://www.dembeck.de/cgi-bin/ttZrupcq/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-20 06:45:4077dc94d7a2eb1a8f1f2875ee18a8115333a3c2ab0f0455d8cd46b952f93809b8docHeodo
2020-08-20 05:54:061a7a1a119f23f5e82bc46e3b7edce0a7a1d0b9b8b6a1fe7962533d61aa932643docHeodo
2020-08-20 05:15:036caf84cf6a6cadcdf4aa5f45a9f87b63c16cdf6486f53279c0ce48676edfc142docHeodo
2020-08-20 04:51:12c5efc23a6bc4da1660b4c6c3b4755581990f7c00591cfdce1350df652c03a3f6docHeodo
2020-08-20 04:29:39b26d580deb9ff666c0dc35f4cc7c9d88038fe0f3c8bf48c4aacd56dfc05c4cabdocHeodo
2020-08-20 04:01:3229524d934f54a27deecaedd3e58de8a4490eddc04ac913bcb37c3ca1354c5b06docHeodo
2020-08-20 03:39:15580ae2c3801f24f8be8cc24b136f1d795787ace030c75c837410f5d827ca02e5docHeodo
2020-08-20 03:25:43eeb0a1417b5106cfb471ec4c6404b1acaeee3e4acfd04ae2748adee4ed69812ddocHeodo
2020-08-20 03:09:44c87f4bdfa6467b9965457be5f3000c92e8115c4df1d44a926577901e5e0eb5dcdocHeodo
2020-08-20 02:51:4760bb16533f938460519528657d8b785485622e3471330a87fa5894fed506eed8docHeodo
2020-08-20 02:37:015debb0401a79585a656197d49e148048a7c7db909c234ae80dd84798e89663cfdocHeodo
2020-08-20 02:21:01b32f302c129728edd895136f299f0e68031f9554b42be4fd2dd35f80a9b2a750docHeodo
2020-08-20 02:00:54be8b2b9dcb90fbaed4e7bc6186fd5dbad93c77fd80cee44717c88ac07641368adocHeodo
2020-08-20 01:43:5796f7d13cfc1edad4f9381ae98cab2336d39557b2230d88583c92284d6616b4e5docHeodo
2020-08-20 00:11:53f49f483de9c2f5fc441b529eaa889631aa5a272206dfdca519993427403f65e9docHeodo
2020-08-19 23:55:14a75897a4101123281bbe047444001acc874171e15cc5a6047baa32d5100d4237docHeodo
2020-08-19 22:53:3536a290d9df91c6881e6f23de7e03e02206ef7ca2d8aac9d585308806b6e2b965docHeodo
2020-08-19 22:25:58f0a83f24371ac4a144149c12aefa268138bf5a01f1c4d062a9e754b6995a1ecbdocHeodo
2020-08-19 22:08:25038f9798da3df2c253620a2fd844e48c6d1a331e314d44196df45b0f9bedffdedocHeodo
2020-08-19 21:50:38d3cea7588b6e664da8ef52bfb856e6fdc6e0df460f961066491aed88f4e29a03docHeodo
2020-08-19 21:36:1600b4f579cad0d3464fb13fe37392ccfb2f41173eb6e505da9c64d7212f5ff8f3docHeodo
2020-08-19 21:16:02bc5f7faf4b9266301e7e8bd3f6ad494c0b34e984278b3a484c6c46d845d9a28fdocHeodo
2020-08-19 21:01:351a17af806d615019154f0985010aad3789bd90bdb40970f78cd0cda2bd722896docHeodo
2020-08-19 20:51:074c599edaef64d08c1377c6c9bf410ed00a513ce17580425eceda35260e50de7fdocHeodo
2020-08-13 11:45:07f844331d28cf2533981a9e753d6df2e9677efadaeea9b2c014266991ae78280fdocHeodo