# bh.tcloudbaseapp.com.ouowoh.cn — MALICIOUS > Avoid bh.tcloudbaseapp.com.ouowoh.cn, a phishing site mimicking a weather tool. Do not enter personal info and ensure your security software is updated. ## Summary PhishDestroy identifies bh.tcloudbaseapp.com.ouowoh.cn as a medium-risk phishing domain that posed as a weather widget, labeled '天气小工具'. Such phishing sites trick users into divulging sensitive information by impersonating benign services. This phishing domain leveraged the guise of a weather tool to lure users into interacting with the page, potentially harvesting credentials or personal data. Despite being flagged on two security blocklists and detected by 9 out of 95 VirusTotal vendors, it is currently offline, preventing further harm. If you visited this site, users should immediately scan their devices with updated antivirus software and avoid providing any personal details. Changing passwords associated with any submitted credentials and monitoring accounts for suspicious activity is recommended to mitigate any potential risk. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 0) - Page title: 天气小工具 ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - IP: 35.220.253.102 - IP Country: HK - IP City: Hong Kong - IP Org: AS396982 Google LLC - SSL Issuer: none ## Detection Status - VirusTotal: 9 vendors flagged Vendors: ["ChainPatrol", "alphaMountain.ai", "BitDefender", "CyRadar", "Fortinet", "G-Data", "Lionic", "Sophos", "Trustwave"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/01989336-61c5-7077-aa79-00ef67da3ed9.png - Cloudflare Radar: https://radar.cloudflare.com/scan/77a978a2-2ac3-4a47-b338-5b0ffd0ca499 - PhishDestroy: https://phishdestroy.io/domain/bh.tcloudbaseapp.com.ouowoh.cn/ - LLM endpoint: https://phishdestroy.io/domain/bh.tcloudbaseapp.com.ouowoh.cn/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bh.tcloudbaseapp.com.ouowoh.cn/ Last updated: 2026-03-19