URLhaus Database

You are currently viewing the URLhaus database entry for http://wonokerso-tembarak.temanggungkab.go.id/assets/7358QZHPBGB6020355/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1967861
URL: http://wonokerso-tembarak.temanggungkab.go.id/assets/7358QZHPBGB6020355/?i=1
URL Status:Offline
Host: wonokerso-tembarak.temanggungkab.go.id
Date added:2022-01-11 17:24:08 UTC
Last online:2022-02-06 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 17:25:08 UTC to noor[dot]ayyub{at}temanggungkab[dot]go[dot]id)
Takedown time:25 days, 19 hours, 32 minutes Bad (down since 2022-02-06 12:57:41 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-126407369_9987.xlsmxlsm 79f8dcc976b6b81642c3f1572e6e8fa219d00828b6b9015e969a50bb38cefba8Virustotal results 10.00%Heodo
2022-01-128939NSHSM_68.xlsmxlsm 697ea1260245ebb08b7387e6d6f4eddd9f9d37d4849abb996244b79526827a11n/aHeodo
2022-01-11X-49513.xlsmxlsm 2bcd5baa2d280f6afd51a5beb204c382fce0fa58f20ff76076d27cb2323e8ac6n/a Heodo
2022-01-11VWG_2761.xlsmxlsm 6ec9e504112744f9f07ce60fb9315cdcd427d27a16c248fbe9746477bfc851afVirustotal results 9.68% Heodo
2022-01-117773-421.xlsmxlsm d232986e906c448669c346c5edefc1d51b9224b6d53afd360e4768f9861eafadVirustotal results 9.68% Heodo
2022-01-11KhB7.xlsmxlsm aa920a2c74b8982c5dd77f97f0dd2d6c7fd69f047983447d6ae43cdf1573b07dVirustotal results 9.84% Heodo
2022-01-11dXOzem-737949.xlsmxlsm 2a43f2180ac8723fc79222c637ad6743128611c7c89843cec720bd884dd1b72fn/a Heodo
2022-01-1164794AQK_580555259.xlsmxlsm 8ad61be673c186c9cdfb6c6c8d750fbcf80f920d4905742c0ed9d67833026ed7Virustotal results 9.68% Heodo
2022-01-1174-60414.xlsmxlsm 71da6e57fe5adfa0b06f8ba9525e6db95e7c25246179fa8563561d24e79e6c65n/a Heodo
2022-01-1112607804829.xlsmxlsm c4bc03a927a72a21be0b15c8c55124264c456a940a325d8071f5cbcb7032f1c8n/a Heodo
2022-01-11006_6546.xlsmxlsm c2cb81db208398e070c47e7d03e76709142dec85ddaa985883536283a0acbb14Virustotal results 9.84%Heodo
2022-01-1127-749.xlsmxlsm be28d13f222be634d640dd982c04039f80c9ada5efc2eb126adca4c9a3595d6dVirustotal results 9.68% Heodo
2022-01-11oc_47104034.xlsmxlsm 867a5e845a227cfb9fa1988fa078679d6b6fa0bae43ffebfe412f97bba373ddfVirustotal results 9.84% Heodo
2022-01-11PnfB685.xlsmxlsm 95761ae4efbb60ee498b7d56d6c84e48753a21ab59a655f5439b47167baf6ea2n/aHeodo
2022-01-111919_03898730.xlsmxlsm 00c8843cc08ecd83f55f5b22eeeef2c14ff4207192bac3795cb0409569b2defbVirustotal results 9.68% 
2022-01-11WF_057.xlsmxlsm 9130d8068b2ef10c7127ddbc23715591e0bd026c0ce94a36c26d92b99ee8e524n/aHeodo
2022-01-1147757199585741.xlsmxlsm 697527009070e730447f346637ff5ff6ad458be500e870bfed11d033c4015631n/a Heodo
2022-01-11974198088.xlsmxlsm f84d3863143cbe9c97859d10c99e61155092470c08e9aee090365490450a4f00n/a Heodo
2022-01-11497014273.xlsmxlsm b0118f2c4a1ae4681d95b8b513b2268ea613ff23d476e806ee7d906f90c8c2fcn/a 
2022-01-11SL_71.xlsmxlsm 6913af2de9271a92bd9c7c9afe4923a08f237459d7e1e03d171e96fa291e39een/a Heodo