URLhaus Database

You are currently viewing the URLhaus database entry for http://p2db.fitrahhanniah.sch.id/assets/JSTPF_8826531/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984542
URL: http://p2db.fitrahhanniah.sch.id/assets/JSTPF_8826531/?i=1
URL Status:Offline
Host: p2db.fitrahhanniah.sch.id
Date added:2022-01-17 21:02:07 UTC
Last online:2022-01-19 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-17 21:03:10 UTC to abuse{at}jalanet[dot]co[dot]id)
Takedown time:1 day, 7 hours, 47 minutes Poor (down since 2022-01-19 04:50:31 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1804773371985176.xlsxls 92bf6d722708e0e9428275c7d0789a52e3fefca383f020e0b8a9cf32e01fb954n/aHeodo
2022-01-184735310083462397076.xlsxls 853bf53e1de361a8c42c16b3a74dd673f990ca41f7f540ab98004a9a39e60725n/a SilentBuilder
2022-01-18144612413869188360.xlsxls ee8b7476fa35280678b3b70ee6f8142bb7945783f64da2a541c0a42e0e804506n/a Heodo
2022-01-187943290980.xlsxls 6e4b969192c1648bf70e8a371d404eb2c612c6d1868141bfcd15ee165bdb0715n/aSilentBuilder
2022-01-1834859348449492271.xlsxls 6d894e2cd1eaad5f13a55f94de79b6dc01a1f37c48b884d488e46003c054eb8bVirustotal results 15.00% Heodo
2022-01-177089503476547424981.xlsxls 6c42a94654de5ebe226d285c0ad13e26b01ba97ec5f8faf8e2fb9411a2fc1380n/a Heodo
2022-01-171453274515.xlsxls d90276f1e57f91966cccef797f36ba18dfdc19cf92a4505d0f59f2421f4eb2ban/aSilentBuilder
2022-01-1709835681067285809.xlsxls 6c45d08768b929c1e9e51c06e8e11e0f679c9a66a33415a427417ee1a3391ee0n/a Heodo
2022-01-178050673525939.xlsxls ab2bf047df74757d07005fc84ec15055dd7ac5a47a765b547e5b5764da471e85n/a SilentBuilder
2022-01-17552649892532385.xlsxls b57b7792f2d74379892499f9a23972aed0b7206a9041b5e3b0720b2a683c0d53n/aHeodo
2022-01-1725035382_49.xlsxls e492f31ca20d99888b2434dcb4d9af1f93ed4c485b9bd2bc550ce8ae8021b9cdn/a SilentBuilder
2022-01-1778848-04138.xlsxls d786500c90a058e4f9fb3611f21c3c3854c9dd23c9a6925a21bcfd850cb8aa1cn/aHeodo
2022-01-17OEWI-3.xlsxls 1dd853714ff0b37fb99d633c608c2c58ca7ad897a8c728308da056706962298bn/a SilentBuilder
2022-01-1790123777.xlsxls dc1149a410dfa7ff3c58eb61f57fd39169b774f8ac21a9554e9227fbb1528816Virustotal results 20.69% SilentBuilder
2022-01-1734374_36.xlsxls ab5d55fb39f73d1da2f46b54b81c0f720e5c6585ac2f41d074ed77434fbf65e4n/aSilentBuilder