URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: naturalwaterresources.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-10-23 17:57:02 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :437

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-08-04 23:32:41 92.113.23.67Not listedAS47583 AS-HOSTINGER- DEyes
2025-06-03 15:27:44 92.113.16.42Not listedAS47583 AS-HOSTINGER- DEno
2025-09-15 16:17:00 92.113.23.164Not listedAS47583 AS-HOSTINGER- DEno
2025-08-07 12:31:20 92.113.16.158Not listedAS47583 AS-HOSTINGER- DEno
2025-08-24 04:04:47 92.113.23.146Not listedAS47583 AS-HOSTINGER- DEno
2025-10-30 21:01:56 92.113.16.125Not listedAS47583 AS-HOSTINGER- DEno
2025-08-29 07:13:35 92.113.23.201Not listedAS47583 AS-HOSTINGER- DEno
2025-11-15 03:10:41 92.113.16.140Not listedAS47583 AS-HOSTINGER- DEno
2025-07-09 10:21:03 92.113.23.255Not listedAS47583 AS-HOSTINGER- DEno
2025-09-19 09:53:33 92.113.16.46Not listedAS47583 AS-HOSTINGER- DEno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-10-29 17:38:10http://naturalwaterresources.com/wp-content/BaHtb/Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2020-10-29 13:18:04https://naturalwaterresources.com/wp-content/Ba...Offlinedoc emotet ext epoch3 heodo ext Cryptolaemus1
2020-10-23 17:57:04https://naturalwaterresources.com/hzqx9t.phpOfflinedll ZLoader ext p5yb34m

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-10-29 21:04:582efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfdoc Heodo
2020-10-29 20:59:332efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfdoc Heodo
2020-10-29 20:36:15b646a2f2855c1348d2d8cbdf2d3f54747bcd727069000f64e1bd824991732442doc Heodo
2020-10-29 20:34:49b646a2f2855c1348d2d8cbdf2d3f54747bcd727069000f64e1bd824991732442doc Heodo
2020-10-29 20:16:33824b555ab78a9670b9a6f46138f71620ac8a363dd7e6d8009bad404dcffca81fdoc Heodo
2020-10-29 20:13:35824b555ab78a9670b9a6f46138f71620ac8a363dd7e6d8009bad404dcffca81fdoc Heodo
2020-10-29 19:47:35b35e8c1cf63de1025db2d2f786b3252b88272d9bad9576c7e2a223a9b4187663doc Heodo
2020-10-29 19:45:49b620242d81548da725331ab89065055cf2766d259d918733cc3a33c91e309adedoc Heodo
2020-10-29 19:31:02490447ab0221c1d099b57c81080eeddf31c23a6b90f4e753aaa82be8e80aefacdoc Heodo
2020-10-29 19:29:22490447ab0221c1d099b57c81080eeddf31c23a6b90f4e753aaa82be8e80aefacdoc Heodo
2020-10-29 18:56:37739b604f19e74fa2a4c12ca8e77df879b1ea0fbde304cf63d53247285e5f976ddoc Heodo
2020-10-29 18:49:29739b604f19e74fa2a4c12ca8e77df879b1ea0fbde304cf63d53247285e5f976ddoc Heodo
2020-10-29 18:46:297035a94379b991e446531c0965b4935f1d3be9a10b20dd97e7dd1e34e6571707doc Heodo
2020-10-29 18:15:260d30a2f25c077dbaa89fd166e0c2e24a2d75900432ab850d5c00dbd826ff759fdoc Heodo
2020-10-29 18:11:510d30a2f25c077dbaa89fd166e0c2e24a2d75900432ab850d5c00dbd826ff759fdoc Heodo
2020-10-29 18:04:15092adc3e63864e36764ee209d07e652c3b37b55e0f433d9ae5c69a1619a482a5doc Heodo
2020-10-29 18:03:17092adc3e63864e36764ee209d07e652c3b37b55e0f433d9ae5c69a1619a482a5doc Heodo
2020-10-29 17:38:10324aedabb0f28b770abb91d9a80adb7075c17d446112ef40261ec9b469e450b3doc Heodo
2020-10-29 17:36:056510c1088251e05cfe18fc22279a7312308f08614ba3dee7852e6b1342e21dd6doc Heodo
2020-10-29 17:19:06ce26d68de2263ab355558dd9f0b201883404c91ecf3f164c8ef0bf17c9e98f20doc Heodo
2020-10-29 17:02:32015aaecbeea372d2cde18c72ef93ce742b3e8c3ddf7247918403295dfa7357b5doc Heodo
2020-10-29 16:16:5062da1d16914ee7b918b84c1bfd2714584b9f6a979558c8e3c09c779b4b30deeadoc Heodo
2020-10-29 15:46:201c6a68700c5a829d8c421561d670c1f86cb25027af4b54be19724b1b7a979ef5doc Heodo
2020-10-29 15:29:339143453f9dd04d35a094a0332fdc37a1d517cc582db210673a79310a26505e65doc Heodo
2020-10-29 14:50:521d56ca58b9d83ed2dc74559beabbc4022b781bfee0f365d9997e3ff099bd6d5fdoc Heodo
2020-10-29 14:26:18094ec2bccb21b949d59963a6a17be2b816cdb626b5e91622ecc64a01fb16fc92doc Heodo
2020-10-29 14:08:56b923e2eb612bd13c6a6ee664b62eb77a9ef516772bcbc77f5bdd50dc255337cadocHeodo
2020-10-29 13:40:106793bb2d87fdd82f3f3be7463704436bae5b6dd4c0f25b34d2da3caf0ec5548adoc Heodo
2020-10-29 13:18:043bbd2607e23ff082929cad28a957e8e1096e5419ecd6e56856d3504b946a12bfdoc Heodo