URLhaus Database

You are currently viewing the URLhaus database entry for http://warpufa.com/cgi-bin/lfNmGWx7Tex3skkRnqmeu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:768873
URL: http://warpufa.com/cgi-bin/lfNmGWx7Tex3skkRnqmeu/
URL Status:Offline
Host: warpufa.com
Date added:2020-10-30 09:56:04 UTC
Last online:2020-10-30 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 09:58:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 52 minutes Good (down since 2020-10-30 13:50:42 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30ARC_6G1B5RAF.docdoc 2d3d4e0033829c37a82f24c6499a0786dc993903374e611aa94c4973a4066dfen/aHeodo
2020-10-30KOU_WEN_100120_PTN_103020.docdoc 289f8b4babc8f697bcbc3125ded9cfddefa96b986243538034beda8361d69a26Virustotal results 26.23%Heodo
2020-10-30mes_01199865.docdoc 0406910d3c48dbd18d57086dcab9b4f73a8081dae9fac3010f0ae90b73c7c34fn/aHeodo
2020-10-30doc_72613195.docdoc 665ca5b6b8e24008d94bd73e8fc3862a558d2074f35ab952eb016e2ecfb2c125Virustotal results 26.56%Heodo
2020-10-30K21IEI9DLAFAB4L.docdoc 6a56325cee2a2a8f5e25ea794eac07e6822aafb9390f367bcc90bccc80090aa6n/aHeodo
2020-10-30FILE_21318476.docdoc 1ce95602afd3133a2b2f7ac1df3290e233ba27b2f2b71d6a1b407cda2cb4ca4dn/aHeodo
2020-10-30Attachments_1765448856373116227.docdoc f2413a07e3362999d85fbab3f6c2fe8f228e4567eac899cd565ad65a2d0eede9n/aHeodo