URLhaus Database

You are currently viewing the URLhaus database entry for http://pantaiharapan-berau.desa.id/cgi-bin/invoice/lmkwu1/hz8397-374316-77673-ec8jd7-kwvikth6m4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290138
URL: http://pantaiharapan-berau.desa.id/cgi-bin/invoice/lmkwu1/hz8397-374316-77673-ec8jd7-kwvikth6m4/
URL Status:Offline
Host: pantaiharapan-berau.desa.id
Date added:2020-01-16 16:08:06 UTC
Last online:2020-01-17 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-16 16:10:04 UTC to abuse{at}cloudteknologinusantara[dot]co[dot]id)
Takedown time:8 hours, 47 minutes Good (down since 2020-01-17 00:57:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-16BAL_SO1365633907DS.docdoc 228da1e8833b2deb4570eb45b4cb5ceff4c62dd963e802c3a5b769ca9d28ff42Virustotal results 36.07% Heodo
2020-01-1641896987.docdoc 58284dd1bedbf2c82204eb15cdad07525a70b52ff1729e051ac101c066531ce3Virustotal results 37.70% 
2020-01-16VLQ_010120_XNV_011620.docdoc a1a7bf3c673d0f16683303b44ae4f3aac3b77e1d419397ea09fc45b3a5b9dd77n/a Heodo
2020-01-16Q_6F9JOEQVQUZGKOU.docdoc a9c48a4f2a96384b1fe947448cb44eaadeb7c0a7754cd17a6899c7f6ae31f2e7Virustotal results 32.79% Heodo
2020-01-16Z_VA2584606715WG.docdoc fa978cd717f47c1ee29bb715045047cfb33ac65fb951e80b7bd122d42879021bVirustotal results 31.67% Heodo
2020-01-16358985259.docdoc 8bf5586fdf5c09bd987b2246b8a60988842d2b3ca683a4fdd6f0a698d17909b0Virustotal results 26.67% Heodo
2020-01-16715024021099484007.docdoc 3c99ebde95d760948c4ff5db925c0272ec89b8409d698aab26e5785a42c88243n/a