morlo.net
Classification: Malicious
morlo.net is a malicious hostname. Linked to Emotet malware. Reported by 3 threat sources, last seen 2021-03-04.
Current activity
- Online — resolving/reachable. Last checked 2026-09-21 04:39:26.
- Stores phishing content — Phishing resources are hosted here.
MITRE ATT&CK associations
Malware families: EMOTET (S0367)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Malicious url | Cyber Threat Coalition | 2020-12-14 19:25:28 | 2021-03-04 13:22:13 | malicious-activity | |
| VB.Heur.EmoDldr.28.69743ECD | Hybrid-Analysis | 2020-12-20 01:45:38 | 2020-12-20 01:45:38 | ||
| Covid19 scam | Cyber Threat Coalition | 2020-11-24 22:30:50 | 2020-12-13 19:20:35 | malicious-activity | |
| Emotet | Abuse.ch | 2020-08-13 14:00:52 | 2020-08-13 14:00:52 | malicious-activity | S0367 Emotet |
Tags
emotet covid19 coronavirus scam phishingIP addresses resolved by this hostname
- 2a01:238:20a:202:1156:: (2026-09-21 04:39:26)
- 81.169.145.156 (2026-09-21 04:39:26)
Whois information
- AS name
- AS6724 Strato AG
- Domain
- morlo.net
- TLD
- net
- DNSSEC
- ['unsigned']
- Nameservers
- DOCKS02.RZONE.DE, SHADES15.RZONE.DE, shades15.rzone.de, docks02.rzone.de
- Registrant
- Cronon GmbH
- Address
- REDACTED FOR PRIVACY
- City
- REDACTED FOR PRIVACY
- State
- DE
- Country
- DE — Germany 🇩🇪
- Contact email
- [email protected], [email protected]
- Domain created
- 2001-12-13 11:08:44
- Domain expires
- 2026-12-13 11:08:44
- First indexed
- 2020-08-13 14:00:52
- Last updated
- 2026-09-21 04:39:26