Scan report · 10 days agoPublic

dw2he.handpopdownloadnow.monster

188.114.96.1AS13335 · US
Verdict

Be careful — warning signs found

Automated

This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
Suspicious fileSuspicious content in the downloaded file
a9b45d60-13c4-41ae-a2d0-e31f795753aa.html

Our Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.

Success

SHA-256 336eb755a0b6471e9ae8139368574eccb92d225892e0734a121c7dd84671723b

Infrastructure

IP
188.114.96.1CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
TLS
CN=WE1, O=Google Trust Services, C=US · expires Nov 27, 2026

WHOIS

Registrar
NameCheap, Inc.
Created
Aug 29, 2026
Expires
Aug 29, 2027
Nameservers
johnathan.ns.cloudflare.comlina.ns.cloudflare.com
55 malicious16 suspicious

Hashes & fingerprints

Page capture

Live

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Load
8.96 s · 1 requests
Stack · 2CloudflareHTTP/3