URLhaus Database

You are currently viewing the URLhaus database entry for https://megatrussglobal.co.id/q4avd/KB51iLM7tjjSS565m6vevfSj1HL/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1987378
URL: https://megatrussglobal.co.id/q4avd/KB51iLM7tjjSS565m6vevfSj1HL/?i=1
URL Status:Offline
Host: megatrussglobal.co.id
Date added:2022-01-18 20:26:05 UTC
Last online:2022-02-08 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-02 09:06:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:23 days, 2 hours, 1 minutes Bad (down since 2022-02-10 22:28:14 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-19861086055206404.xlsxls b24ab935f6d7ae64a036e919f70a63590db56ebd6dea1660d89827851be32e93n/a Heodo
2022-01-19531200681205923.xlsxls 2af6631e3481f468b1b17c3008374c23eff67a9f139e56ecc0bb9a0a34016048n/a Heodo
2022-01-1932594094000218774657.xlsxls 0bced3cd2e9c1e23162ba0e5e2ccc316b26f399a22c93a5d2b026017790db3fen/a Heodo
2022-01-1953383094657.xlsxls 0ceb1183ed25dd44ed993229f1f4898fa29af82dca77e7f38082dbb723452838n/a SilentBuilder
2022-01-1930703673207226866507.xlsxls fa118d305bad13e6c33a570a4bcd6159971ca1c5c3cf06eb7c8a5612e0d42aafn/a Heodo
2022-01-1987560814601193033642.xlsxls cff13f579e3598d9be5b751b75baf9fe837772239567fd22224bce3c6e99e1d0n/a Heodo
2022-01-1933463390555736.xlsxls 54c4606892b1fede80e10591041b980262e6a780b2017de3ce6779d96d862a44n/aSilentBuilder
2022-01-1948300277121.xlsxls c425b918e6144021b603d7713891f953c90f3fe0b724c2fd15767e577edb7ba0n/a Heodo
2022-01-19770577885057512.xlsxls ed228873fb44f8cc68edada7c0687dfda287a3ae45fb0c0cb6cf8a58bb2487fcn/a Heodo
2022-01-191112394478.xlsxls 489a8d75e0335e05d649b0e5cae103a142020fe00909e4e1f2d83704f07fff84n/aHeodo
2022-01-198574262229098.xlsxls d26f4a2809e92686fcb04d7e6662638fb1da0e2e7d7dd7057ef7931d1c36f4d3n/aHeodo
2022-01-196922847338.xlsxls f8746c0e7d492357a8f30e424870c4fce49699d165260610a62360668541035an/aHeodo
2022-01-19403543001096518.xlsxls 2973cc99c73795a2e3a00ef11ea792c3800f933fc073fe670d2907261f6c965cn/a Heodo
2022-01-1978781529362667602.xlsxls 14817a3b02e6cb0a22fd6b251c612d2f21ba516c03224741e3ddc24755c424deVirustotal results 17.24%Heodo
2022-01-19918647723642.xlsxls f21410f3f5786c2c2f4baa5678cf8396f3a6999e75fd264b7524489f6e70ee08n/a Heodo
2022-01-1905937726015921989.xlsxls 7bcc81bd2ed657103d32c3786d4ed067a429f084675d83b1a7b4517c48680820n/aHeodo
2022-01-190863148764.xlsxls 44da779f7768dcf98274fb702fc93b89b7c674a2de24c2547f3a765663092d4cn/a Heodo
2022-01-195236889480750933415.xlsxls b8e79d6d4ce2e23e9b126c3397150be331952bae520caad6039e7dfd048c83f3n/a Heodo
2022-01-1959573447653549172550.xlsxls 1477850fa35c92df361237f36a47aec448706db0a3f0b0f0ef411a7ceff580dan/a Heodo
2022-01-1939216660923.xlsxls 2ead439d10213f8992ba0fa9c5a4ad9ef3fa50bf9b2ba0b7aa2ddd01a4e8306fn/a Heodo
2022-01-196607248403994.xlsxls 9395907b748740960ac38d3ba4faeb6248b7953da69f834daff192bb2ff1fff6n/aHeodo
2022-01-194071330198937869933.xlsxls 08326159f288918480978f4ca2d0a705037a18c23e58f779f9bb3bd9fdde6d75n/a SilentBuilder
2022-01-1995957463772744810.xlsxls e65457b2422f5bf91f36b2f1a6d12469325b7b580d3d07262777b764230414f0n/a Heodo
2022-01-1955220122876425945.xlsxls 45436614d9baa751a6da8b87c9736389801dd8daab1a8f82d73aa96f644da316n/a Heodo
2022-01-1929773952365710.xlsxls 8e29493f61aa15b6d8045450c52ede09ff2e5946e88df86409c6a693ce2863can/a Heodo
2022-01-1992641211045062801.xlsxls 3340c74a1202b3e5f9516584a312c057b828436c35a06bbd7c3d0916e9a85289n/a Heodo
2022-01-19720196900351.xlsxls 5b4c4e8767ddfa4938976a941711a1019fcd0f5a903d8a87e3f2bf316db2403en/a Heodo
2022-01-1990229482575087360469.xlsxls f019fca804432459a70c27b9361be7db78f4dcb3754485872c11fdfb1da20e8an/a Heodo
2022-01-198257213324381.xlsxls 76faa078d1f1713f316cf3d152958b0db77d8e9255dd084d902b460fb3ea97cbn/aHeodo
2022-01-192085406455453254.xlsxls 0c4b8e3f9f33c533fb5f6f6aff0802f3fe3f9c0eaeb8bdbf82687c98c999e3ben/a SilentBuilder
2022-01-19444389902618595.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72n/aHeodo
2022-01-1811166816667163019853.xlsxls 95141c557c2da97c647844e7c27133e0f8ba49907e167088ad774ed57e950294n/aSilentBuilder
2022-01-18646621363097.xlsxls 9a0279149641144e4f3152072a4a9b108c98cf39d6deb7471c49736711635507Virustotal results 13.56%Heodo
2022-01-1882352576588.xlsxls e1727c3aaa854ddf777f23d7783fa1a77d690ca625cfa0e70fa04bc42110728eVirustotal results 13.56%Heodo
2022-01-1854542644618.xlsxls f41ec4b22a26f1a4f48f59ab394c650f24c4f44ee6bec9a108bd381c0b7c530an/a Heodo