URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: heufheuwh.b-cdn.net
Domain registrar:Name.com -
Domain registration date:2016-04-25 23:34:57 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-10-24 12:03:09 UTC
Total malware sites :1
A record(s) observed :34

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-12-15 07:15:19 185.59.220.198185-59-220-198.bunnyinfra.netNot listedAS60068 CDN77- DEyes
2022-11-25 15:54:21 138.199.37.225138-199-37-225.bunnyinfra.netNot listedAS60068 CDN77- DEno
2025-09-24 10:18:35 185.111.111.160185-111-111-160.bunnyinfra.netNot listedAS212238 CDNEXT- DEno
2022-12-28 03:52:24 138.199.36.11138-199-36-11.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-12-09 05:44:17 138.199.37.229138-199-37-229.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-11-30 20:23:49 89.187.169.4789-187-169-47.bunnyinfra.netNot listedAS60068 CDN77- DEno
2023-01-27 22:50:43 169.150.247.40unn-169-150-247-40.datapacket.comNot listedAS60068 CDN77- DEno
2023-01-18 04:47:45 169.150.247.35unn-169-150-247-35.datapacket.comNot listedAS60068 CDN77- DEno
2025-05-19 05:00:39 79.127.216.11179-127-216-111.bunnyinfra.netNot listedAS60068 CDN77- DEno
2022-12-06 06:58:18 138.199.37.232138-199-37-232.bunnyinfra.netNot listedAS60068 CDN77- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-10-24 12:03:11http://heufheuwh.b-cdn.net/chrome.exeOffline JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-10-24 12:03:10a6ccbe999228a8ef36443b321573865ddf4dac81e20a586d694d8a2ff4837279exe