URLhaus Database

You are currently viewing the URLhaus database entry for https://winpeforum.com/insx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2731752
URL: https://winpeforum.com/insx/
URL Status:Offline
Host: winpeforum.com
Date added:2023-11-17 19:16:39 UTC
Last online:2023-11-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: k3dg3
Abuse complaint sent (?):mail Yes (Ticket DCU100295017 created on 2023-11-17 19:17:06 UTC)
Takedown time:1 day, 12 hours, 7 minutes Poor (down since 2023-11-19 07:24:14 UTC)
Tags:Pikabot TR

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-18UIAVS.jsjs 826b0de61ac583d99c3e1eaf0f9731b98cc286be4eb9b4e9a8b3bab04e852ccbn/a 
2023-11-18VP.jsjs b8e29c89b93e1738ba4c58dc525795d55ef486cc09228c7ff6acac99ac75c11en/a 
2023-11-17HAEM.jsjs 3987299362f6ae3c7a41a1e8162d8a7c0728722f3034f65e0dbe5584f26aa832n/a 
2023-11-17CEE.jsjs 3668ec813e023d6d1d776612215d744d9922690077e022b31dd4a6ef4f712fa9n/a