URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: pkmtikep.munabarat.go.id
Domain registrar: n/a
Domain registration date:2021-05-06 07:09:05 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2022-01-11 18:03:04 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-11-16 01:57:42 154.26.139.250vmi1084829.contaboserver.netNot listedAS141995 CAPL-AS-AP- SGno
2022-01-11 18:03:07 194.233.89.63vmi1177629.contaboserver.netNot listedAS141995 CAPL-AS-AP- SGno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-01-11 18:03:07https://pkmtikep.munabarat.go.id/5k1s1td/irW4wi...Offlineemotet ext epoch4 redir-doc xls sugimu_sec
2022-01-11 18:03:07https://pkmtikep.munabarat.go.id/5k1s1td/irW4wi...Offlinedoc emotet ext epoch4 heodo ext SilentBuilder sugimu_sec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-01-12 00:59:381b7581c8be4bf9197005067c42e581bcc1c41b10d6d9768daa8c4642f6e3ef7bxls SilentBuilder
2022-01-12 00:27:149e0c891bd4b687d10b5c7d8082a2d4c7d24a0c9ea90b1d0aa09dafa6dee22047xlsSilentBuilder
2022-01-12 00:14:5259f00806db4a68a10acb6aa0f9ea1d21c2e8527ff2b82d0ab36196ba0bda9183xlsSilentBuilder
2022-01-11 23:47:595dd8cf32347063a7b6b80c824526d1f58a3b8c99344eaea74dad15d687395f64xlsSilentBuilder
2022-01-11 23:20:31bfe1c65501eb9a22ea914fe380d24127cdf99ce17fc20683f99a7b1e0ccc06f8xlsSilentBuilder
2022-01-11 23:12:15429e0de91bc404f5fc886f0618177f5bc49fe0da3940e98426c5d5cd8aed57cfxlsHeodo
2022-01-11 22:48:30e48f10cc12e08a32f523982c024f49dca076b06c6bd47b5cdf3d43aee5097091xlsHeodo
2022-01-11 22:17:531b07cb00b2a9790fd3d3dbc858112dc7308a0fa920fbc8a8ba019af5ea216752xlsHeodo
2022-01-11 21:51:28755b4ee15682c5a1e3567c5d710b241e03a8b6ce7080dc3ef0816be9ed6e06f7xlsSilentBuilder
2022-01-11 21:27:309ade9daf48cb63c929cd8e7ec03ac77ed41d362efaa79453d0eda4553747c404xlsSilentBuilder
2022-01-11 21:12:33c7cc8c98988b0b5cdbd103db7c61f01a6e92f96f525c36f15bfaae039bb46cd7xls Heodo
2022-01-11 20:47:48fd3087fa953ec989caff35845ec2bc3cc41303ac26e0f0d0b8e25a325fee3a29xlsSilentBuilder
2022-01-11 20:25:080dec37edf7d179a139b89569d030dc83a715e5d9a945d9dedc410c3fcdd09125xls SilentBuilder
2022-01-11 20:03:2603319a0f6c37911983650f91c2a01b29eac84b17bd99133626d11d08952ad9d4xlsSilentBuilder
2022-01-11 19:37:15c415f6432a14864da8d7cd66dab9263599364b3b1d8b3fd13e4c725d1a0c4562xlsSilentBuilder
2022-01-11 19:17:477b273da870150fa002d6651be951c45565ecfb209c9516b78a60d5e6274d4f9cxls SilentBuilder
2022-01-11 18:47:0018e24e9b03fde05fa41b9d86aa612dbbd5deabcebbe97ee5b3a3b7fa8fb43f51xlsSilentBuilder
2022-01-11 18:25:4860fdf680c8e0272784588bf87ead2814df683a2fcb697522ddd4ef323166440axls SilentBuilder
2022-01-11 18:03:078341284269fca2b118d30428f5ec5b17de257e39b6f26d5777975a43fae04a39html  
2022-01-11 18:03:07f9dc6d359581da286cc014340d248cea2acedf09a9dc0cf9280641f3393fba35xlsSilentBuilder