URLhaus Database

You are currently viewing the URLhaus database entry for https://pelangi.kim.banjarbarukota.go.id/cgi-bin/3NbFuBNM4a3KX/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1987223
URL: https://pelangi.kim.banjarbarukota.go.id/cgi-bin/3NbFuBNM4a3KX/?i=1
URL Status:Offline
Host: pelangi.kim.banjarbarukota.go.id
Date added:2022-01-18 19:14:11 UTC
Last online:2022-02-06 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 19:15:09 UTC to ito{at}banjarbarukota[dot]go[dot]id)
Takedown time:18 days, 21 hours, 10 minutes Bad (down since 2022-02-06 16:25:24 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-195726157731610.xlsxls ddbbb75f6e110b1199806cc6d2a495daf80f8c0f824d5ef9d3efcf9648a0697an/a Heodo
2022-01-1903989877134553060.xlsxls 87282766839abff07098024789f18516dd558d44b54c0489163de87ca8f7a3efn/a Heodo
2022-01-19819416353399888.xlsxls 8d98ecd0f1108c3306f1be597968a3f9de1e00779b42b1447a58ca2dfe62753cn/a Heodo
2022-01-1968878460143768115556.xlsxls 96217b822dd1cfdfddb8a18d96ddd842df8663c1bb791627befe5cd5a4672835n/a Heodo
2022-01-1930934340221.xlsxls 095ed0ef3d38134c16e273bb61c0adf595c3023a598608ce95e68fe92c3640afVirustotal results 20.34% Heodo
2022-01-1927669797675595884.xlsxls 142dc674a687ade3bc56e2e78f0a6dc0603d81f176f8a9d794d909b6839bcc5bn/aHeodo
2022-01-1913387670370733444840.xlsxls 17581147f8499f2af73d7e6c3e66e18acaf2d4acdbec0aafa790384231cc9f8an/aHeodo
2022-01-199993168569382554689.xlsxls aae035c074dd1a0f16ab7381887f6a9f8929c6b8f82d78d8b976bfa14151f8a9Virustotal results 18.64%Heodo
2022-01-19696845790328.xlsxls c90c1b4626812603a3199a0a72c7eeaf6ec5eaccb326c48d2e5795ae26485ee4Virustotal results 18.64% Heodo
2022-01-192437323460.xlsxls 13bb456ae96c767a0b06cc91ad1a28eaeda7ddaa52e58c2f0a459329d191258bn/a Heodo
2022-01-1964254387776303455027.xlsxls 0d495c0696722d948b9985d4c46f507557711c4993886294d85df04a7f16d82fn/a Heodo
2022-01-1938538027548370068527.xlsxls ef091c8fd3da5e55d7349f328528de0c8efbadff875a3a2f4d07355acc5a98d9n/a Heodo
2022-01-19954526348139901097.xlsxls a3784c72e6ab52b51cad774c0df03b581b4f6836c70538e286e5f261a9e45585n/a Heodo
2022-01-19885549342424653576.xlsxls 2ead439d10213f8992ba0fa9c5a4ad9ef3fa50bf9b2ba0b7aa2ddd01a4e8306fn/a Heodo
2022-01-1964016022695612039302.xlsxls 4ea8a2a5f986391336015695a1f48749ea0956a8874d8ffe17cc4b6c0865c9fan/a Heodo
2022-01-193879447641253968.xlsxls 4b1800da594032e6944a2b0728eaa50223d1ca0a6eaf3883ce9a0dc05d2e982an/aHeodo
2022-01-1998521254434961.xlsxls 8a464dfc159ef035f950a356301f0ca156ee957dcca035dd3d3b25071806b490n/a Heodo
2022-01-199980645597.xlsxls 9a1bce939f4cf72c34d855f1bfbfacda0512e0c5498a07a0baab6abf96155166n/a Heodo
2022-01-1908473629408.xlsxls c1205d8c06d1e7c19458a0cf0b1058161767e181aa90a96d49ac188121987fb5n/a SilentBuilder
2022-01-19304124996961.xlsxls 2543badd28fc1740c4784e313fc2627c75b8ffa4ab59f5e79dd74e37973a72ccn/a Heodo
2022-01-19633553539572.xlsxls 24b8fe046cda4e3fabb27cf9e4934ff9ff02d228cdf112425f83a4f71155a66fn/a Heodo
2022-01-1918683929918654359770.xlsxls 18640736a2a44c2a43ebde16c129f4d6e01590736cc7a0c926e1b680f0f11b1dn/a Heodo
2022-01-1973638703665661277353.xlsxls 6b65f37d876f38bcc12bc144f25a9674a7461b5500953b5ff8bf02186d82b3b8n/aHeodo
2022-01-190950609201562.xlsxls 13eaf2acd17c26f3590753935f2733b116f0e2bf68ea6994b2a434df4c72e838n/a Heodo
2022-01-19025670020084436.xlsxls 3171afe617c6e34d38d3126deab77dc7ecc2518765d32043bd6f4ceb4d5fa00cn/a SilentBuilder
2022-01-1980891430145729280.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72n/aHeodo
2022-01-18355065562706.xlsxls 95141c557c2da97c647844e7c27133e0f8ba49907e167088ad774ed57e950294n/aSilentBuilder
2022-01-189129194464033296814.xlsxls 23818d020226a4e303ac78cb6d0a405c556ac097e43103924139863457ce57a4Virustotal results 13.56% Heodo
2022-01-1885531943231.xlsxls c99991580b4b64870f550a0aa0aa4eb26173728dd8fbce2fad2d57d407371437n/a Heodo
2022-01-1839117626161221805.xlsxls bf376a31fa5af8237b08c693771612a511828ac0765970c6cafd53a3058113a7n/a Heodo
2022-01-18725877543709879370.xlsxls 15b65cfc7f62b8ac6fe2d8d616f5576f6504e6e59704535ca692b782e1ad2bedn/a Heodo
2022-01-181578718595586848197.xlsxls 2f3ddb5c2004087063492ae17e39a037f245755cb57c6814782352e84bd6fbdan/a Heodo
2022-01-183712912520.xlsxls e741bef7c65d6536d3a412e743075062e24831d92bc1ef43459c52671d54cefdn/a Heodo