URLhaus Database

You are currently viewing the URLhaus database entry for https://e-kinerja.ntbprov.go.id/aset/sAeaEvaSxGhvnsuFE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2130373
URL: https://e-kinerja.ntbprov.go.id/aset/sAeaEvaSxGhvnsuFE/
URL Status:Offline
Host: e-kinerja.ntbprov.go.id
Date added:2022-04-04 09:48:06 UTC
Last online:2022-04-05 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-04-04 09:49:10 UTC to abuse{at}gmedia[dot]net[dot]id)
Takedown time:16 hours, 7 minutes Good (down since 2022-04-05 01:56:11 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-05KzLslRg8xX1Vj2gy.dlldll ac52d76142116e692db0aa5254ca018374f5cc78e7edc490a12bb9bacda4ab5eVirustotal results 18.84% Heodo
2022-04-04cWrFrZYbCKTH.dlldll fd88683683fb13010e7ba2ab6c10477aa674c523746e6921b981f4bf264d09d1n/a Heodo
2022-04-04nNqqohhpdDov3.dlldll 923276e96f369376b6bcc5500086b218084743d10589cf29e6a4a67b1acffa90n/a Heodo
2022-04-04OJ5vKlpvfQw7RgvACr.dlldll 1fe931edc1c17cd513d3b49c236d04eb4dc8b0ae0e39ffa55e71a34a035576d4Virustotal results 18.84% Heodo
2022-04-04cg33Dcr.dlldll 1560fa9d926fd62a534da64d56c8ff9113f02b3124365277a88a66d944c519d1Virustotal results 17.65% Heodo
2022-04-04scQUjoaLBYInBqoDUIw.dlldll 1f9596efe44d990500d11c66dd0af4ae3e396c8239b601af53eb534f30a2212cn/a Heodo
2022-04-04XFWmAAxJPFFmWesrF.dlldll ca95cbb564d79db64dd141c68b3f58e8288e2a6ce372ec4010efaa16cf1a39deVirustotal results 11.76% Heodo
2022-04-04Gj8k6nlEMHp1.dlldll f566a9cc5ef3a7e69556c563a69e4553d71b6d018781fe9040724c29a2136ac5n/a Heodo
2022-04-04oL16xat8.dlldll 6647aacf1fab9014205cbe5f1fb2d0846fe0da0c4109aca046fca7966ccd8d07n/a Heodo
2022-04-0477o.dlldll 03637f92683ea1272d7af740015827d7d512d337b716a37ea694af1db9b38f77Virustotal results 21.74% Heodo
2022-04-04m2vrRaTmHHOqcXeLZhR.dlldll b8f485ac6799b81e3855b6d4cce233174a804c7fe08fe7d2b1dcc7dc22f3c07bn/a Heodo
2022-04-04m1VdYLIzmlxvxX1UNgQ.dlldll 291e7490b6db098aac706b0d00c747cb058ff43a6f996bc5ef00259d93c037d6Virustotal results 20.29% Heodo
2022-04-04BhJGLApaLRc.dlldll bcbe4906d20108bf648d1e98ec8043cce8bd45966431583f68bd7d0d17978c20n/a Heodo
2022-04-04BwADL.dlldll 89893c1b19999c69a822ed2fe75b07e10b6ab98e8aea180dbbfb191d02a7f46fn/a Heodo
2022-04-04hdXeevdB7.dlldll 7463cb8451fa2d61e3bf60390609aa4f23fc07369bcffbc579b1e95e48d5e0bfn/a Heodo
2022-04-04BLIoFMivA054jQ8hclY.dlldll 0cc8600582c3105e4d307840535ec5a671cbd65615580c6a8ab366d50a81e5adn/a Heodo
2022-04-04NYoNcI07KCHeuvp1H.dlldll 0b6de5f41fe89c8e0fae83c2d7b647832bf4404b497895cb4e22781958b4e9ean/a Heodo
2022-04-04ArGTwJA.dlldll de85516484be859573ad24a1b3e492782efef3fceb9b2a6fcc1fcafbcf70df01n/a Heodo