Summary
API
This website contacted 10 IPs in 3 countries across 14 domains to perform 92 HTTP transactions. The main domain is gmx.net and was registered 14 years ago.
Submitted URL: https://ultahost.gl
Effective URL:
AI Security Verdict
Moderate Risk
Confidence: 65%
Entry domain ultahost.gl carries a CountLoader malware Indicator of Compromise (single-source) plus a HIGH Spamhaus IDS alert. It redirects to a legitimate GMX consent page with no credential/payment forms, but the flagged domain warrants avoidance.
Risk Factors
Safety Factors
Details
Page Title
GMX - kostenlose E-Mail, Cloud, Nachrichten & Freemail
Scan Type
public
Domain Name Analysis
The domain 'ultahost.gl' uses the Greenlandic country-code top-level domain (.gl) and has no subdomain. Count 8 characters in 'ultahost' with 3 vowels and five consonants. Word splitting yields three words: u, lta, host. Expect three characters per word on average. No strong language cues emerged from the frequency lists.
Screenshot

Page Load Overview
Language Analysis
Primary Language
Detection Details
Website Classification
Primary Category
All Detected Categories
Detected Features
Domain & IP Information
| Requests | IP Address | Location | AS Autonomous System |
|---|---|---|---|
| 11 | 176.65.132.18 | Amsterdam, North Holland, Netherlands | AS197170TechTies Inc. |
| 9 | 23.52.180.183Akamai · CDN | Frankfurt am Main, Hesse, Germany | AS16625Akamai Technologies, Inc. |
| 9 | 217.72.199.64 | Germany | AS8560IONOS SE |
| 9 | 2.19.216.191Akamai · CDN | Prague, Prague, Czech Republic | AS16625Akamai Technologies, Inc. |
| 9 | 217.72.199.29 | Germany | AS8560IONOS SE |
| 9 | 217.72.199.51 | Germany | AS8560IONOS SE |
| 9 | 217.72.199.120 | Germany | AS8560IONOS SE |
| 9 | 217.72.199.1 | Germany | AS8560IONOS SE |
| 9 | 217.72.199.24 | Germany | AS8560IONOS SE |
| 9 | 217.72.199.68 | Germany | AS8560IONOS SE |
| 92 | 10 | - | - |
Detected Technologies1
Content Similarity HashesFor malware variant detection
TLSH (Trend Micro Locality Sensitive Hash)
Specialized for malware detection and similarity analysis
ssdeep (Context Triggered Piecewise Hashing)
Detects similar content even with modifications
sdhash (Similarity Digest Hashing)
High-precisionHigh-precision similarity detection for forensic analysis
These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.
Image Hashes
Perceptual Hashes
Other Hashes
Scan History
Scan history not available
Unable to load historical scan data