URLhaus Database

You are currently viewing the URLhaus database entry for https://sipandu.hulusungaiselatankab.go.id/documentation/statement/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303023
URL: https://sipandu.hulusungaiselatankab.go.id/documentation/statement/
URL Status:Offline
Host: sipandu.hulusungaiselatankab.go.id
Date added:2020-01-30 15:48:09 UTC
Last online:2020-02-02 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-30 15:50:03 UTC to abuse{at}iconpln[dot]net[dot]id)
Takedown time:3 days, 0 hours, 24 minutes Bad (down since 2020-02-02 16:14:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01JV2336641156GL.docdoc 8ef3a86989c9654cd7b0914ab743459ad98702ea960612c66e331f858a791eb0Virustotal results 45.31%
2020-01-31DOC_PO_01312020EX.docmdocx 12f17aa88c41cd66c648d4f19289192958e721c494829eb67962060967d804beVirustotal results 42.86%
2020-01-31PAY_020006282239732.docdoc 214d5a002c69788401e88128b4532c65e84c31018aadda1fdd7badc5bd1b16adVirustotal results 41.27% 
2020-01-31SW_PO_01312020EX.docdoc 490e43ebe2e9f9222605d29f2786989ecbefca72897bd9b172d3e893dc3a2493Virustotal results 39.68%Heodo
2020-01-31O_PO_01312020EX.docmdocx b2b0dc6852bea40e3dd6253292876a67f820441f13e9da1c5e2f415654694f89Virustotal results 41.27% 
2020-01-31PAY_PC9751284801KV.rtfdocx 09adf985e1905209ed2ecfd3e6576e740cf878a09724b41885b6a60311f1c734n/a Heodo
2020-01-31REP_377966622462.docdoc 6971378f1c7eccd93a6ab7cf3dd5ea551a5ca14cf564e121f883c2f364e46876Virustotal results 33.87% 
2020-01-31DOC_PO_01312020EX.rtfdocx 4e2b359f6af536b5b64747340cafc480a9ca13749929b951a2db7d5f18b00facVirustotal results 34.38% 
2020-01-31N5DC1TW6.docdoc 1b75dd0fa245e88d26cb1ca67bcc5a5c0e515a1a61e11ecf77f962989f3072d4Virustotal results 34.38% Heodo
2020-01-30BAL_O5SVI5DTHAC.rtfdocx 38204212a0f251cce3f9bbbf3ba8c8e3ff7f3fe44216b48f6ad339e691500d16Virustotal results 37.10% 
2020-01-3009147387.docdoc 201abdb8d9d94e5edac0b0e5da31b12f15e30a68967998f103247779f84f6311Virustotal results 37.10% Heodo
2020-01-30E2B77JYU3OU.docmdocx 52c6720f0932a23794efd7a0b1c22001fc074cf6fc3fe710124bb0750c7bf045n/a 
2020-01-30SW_40093602.docdoc 1989a1ba92b07553f5089bd063e76edafddfcd4c53774fc697c8835d7f10adb5Virustotal results 34.92% Heodo
2020-01-30DMIB_PO_01302020EX.docdoc 1b5d6a9fe7a562d4d940efb272ceb962dda14a0cb672a089fe2a0ed20585c0a0Virustotal results 39.06% Heodo
2020-01-3057675304.rtfdocx 2bbd0a508235db55965768eebdb553f4bc7457a1d5844e11c2c34176ff37f139n/a 
2020-01-30H_FMB_010120_QMO_013020.docmdocx 3476381f8a76d5131391144afc9072ad6ffb33c7cdd6aeeb721600c5743992e0Virustotal results 34.92% 
2020-01-30SW_18060288.docmdocx 40520f763acb971389175978656d2f9c5d0b79e32f996b497f7748a0891ce742Virustotal results 37.50% 
2020-01-30ST_PO_01302020EX.docdoc e43f667eb19772a36236856dbb823747cbe46ad4fc681f1afc94bdd18e7d7ef7Virustotal results 35.94% Heodo