URLhaus Database

You are currently viewing the URLhaus database entry for https://fitrahhanniah.sch.id/p2db.fitrahhanniah.sch.id/PR-8897/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1975157
URL: https://fitrahhanniah.sch.id/p2db.fitrahhanniah.sch.id/PR-8897/?i=1
URL Status:Offline
Host: fitrahhanniah.sch.id
Date added:2022-01-13 22:53:05 UTC
Last online:2022-01-19 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-13 22:54:07 UTC to abuse{at}jalanet[dot]co[dot]id)
Takedown time:5 days, 5 hours, 51 minutes Bad (down since 2022-01-19 04:46:06 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14F77.xlsmxlsm 55b280b05c955ebd0ae9d14627c4ae01e7a9c241852874f63686126fc09b9d17n/a 
2022-01-1426917_82155.xlsmxlsm d55979fab69e6383de91fecd3232f4f013cc7eb8de5a4a0090c6e0a371765b4cn/a 
2022-01-14anKV_110.xlsmxlsm 9c8a39e1e2d7547aebadc4f37b84543d9e48faca443b9acd76cdf46d65459acdn/a 
2022-01-14620301_0569.xlsmxlsm 3dd7791745ef386d30fdac27e392533cbf154de6881440bf6bae3b947c775402Virustotal results 24.19% Heodo
2022-01-14818171814_6126696.xlsmxlsm 4eab3977f88e6444a99925c2a5769e6b720e8a6ba4ee8cc8235e23a33a1e6658Virustotal results 24.19% 
2022-01-14UHGN_04.xlsmxlsm 1c240992b743818ab5c0ee5f4de32be4555853fde4d92d8f8264dd975f5ae3b3n/a 
2022-01-13buBDSV_003585.xlsmxlsm 3761b25fa3d41a38d6d55c5e87d4a89bd1c35bdf0d06d744642ddbd14c852964n/a Heodo
2022-01-13288538526.xlsmxlsm 6988f7d044aba01c32dfd1a18e12f8a22021287669837002631609031be20c01n/a Heodo
2022-01-13003_4211983.xlsmxlsm d8975b3d34180a07691e5a123247eac7e5f33d89c49119fa1d629bd27762e25dVirustotal results 24.59%Heodo
2022-01-1369723_426288.xlsmxlsm 4e5cea7406c6c936d505399f9abb77ec9d468062e66010f0b3cb4cdba9017aeeVirustotal results 24.19% Heodo