URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: bwh-reservations.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2019-04-05 17:37:58 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)
A record(s) observed :3

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-12 00:50:26 172.67.152.176Not listedAS13335 CLOUDFLARENETn/ano
2025-11-12 00:50:26 104.21.72.158Not listedAS13335 CLOUDFLARENETn/ano
2019-04-05 17:38:00 159.89.81.236493710.cloudwaysapps.comNot listedAS14061 DIGITALOCEAN-ASN- USno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2019-04-10 21:45:06https://bwh-reservations.com/wp-includes/kmbk-b...Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1
2019-04-08 19:55:05https://bwh-reservations.com/wp-includes/kvi/Offlineemotet ext epoch1 exe Cryptolaemus1
2019-04-05 22:49:33http://bwh-reservations.com/wp-includes/keQb-WE...Offlinedoc emotet ext epoch2 Cryptolaemus1
2019-04-05 17:38:00https://bwh-reservations.com/wp-includes/keQb-W...Offlineemotet ext heodo ext spamhaus

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2019-04-12 20:18:19804b01b391cf622f6207d52fd43586ff8323ce6209873f2bf92609e4ef959a1cjs Heodo
2019-04-12 19:47:37a54bec880c16ff7c6e6b82504263a93abbd21682114d7a748a6e374d3a712f36doc Heodo
2019-04-12 18:11:42cc2b5224a9d1331460439d49a3295a044b45274753207fe28ddbe9760ae06f98doc Heodo
2019-04-12 17:40:33a337638a8cadf540561aed4ec545415e5b2502216a08d8fe426c5a717ee86c67doc Heodo
2019-04-12 17:08:397b8e0e43c6fc604494de61789257c020a623d8da87965b427cba5d3ae0afe170doc Heodo
2019-04-12 16:37:429ff3aaa377fbdb25692e2c9624a684af93324259564ac9921f31b439d9be3e22doc Heodo
2019-04-12 16:05:40661f7d9aea272c78f3b9ce42bcafe6062e48e5ff803b1dfd9c11b3c8053b2ea6doc Heodo
2019-04-12 15:03:50c892bc440d5444b162ce0d9b5255ec2e006a288563c30f1993cb3b7beaef98dedoc Heodo
2019-04-12 14:32:42323c0ef4ac6d8f00c2fab49442378460f64ad686349b3469dbb56d20c3cf05b2doc Heodo
2019-04-12 14:01:51e5472360bcb105587d0d8e755a0284c5cdd5337646e40bb1e8fabeea870943c8doc Heodo
2019-04-12 13:30:3521ba2d695d49981f692fd04754c34f7c887d634d043da15fc9fd254a52a57805doc Heodo
2019-04-12 08:51:181f18a298cc1cdd9527f5345e3ac6438cadffdbf62a1f2a4dc69a22a626980c41js Heodo
2019-04-10 21:45:0626b5d6c8934dbf593f2cc541bacac6e7812d71ddec256eb7bb4e9dd61b9c13b4jsHeodo
2019-04-08 19:55:053521f9acd6139fb596a07a1292da86eef4ad2c47fca1619903d41bc4fe23e7a7exe  
2019-04-05 17:38:00ffbe73591031973cb52f6950ed61b168a0f0bda69f004db08846dfc1bd1d1920js Heodo