URLhaus Database

You are currently viewing the URLhaus database entry for https://kalumpangkec.hulusungaiselatankab.go.id/wp-content/uploads/cF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:309029
URL: https://kalumpangkec.hulusungaiselatankab.go.id/wp-content/uploads/cF/
URL Status:Offline
Host: kalumpangkec.hulusungaiselatankab.go.id
Date added:2020-02-05 12:51:07 UTC
Last online:2020-02-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 12:52:03 UTC to abuse{at}iconpln[dot]net[dot]id)
Takedown time:2 days, 19 hours, 8 minutes Poor (down since 2020-02-08 08:00:23 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07INVOICE-K632_53244586.docdoc 03f1c572286d806b767e9798f4dbe54a7b3f3509096d3e1040c2ff2941ff6028n/a 
2020-02-07invoice 8_23085748.docdoc 8f0ab8f306c8132ff855166d634beca3f36434bc251cb2902c2007e16acd004en/a Heodo
2020-02-07invoice VMT5_44540250.docdoc 2520f66950aa31c64dd4d5a7cfb22687529e99bd10320e593bdd608fa7d128een/a 
2020-02-07Invoice_6_2060654.docdoc 3078e9310437cd53e82bb9cc5679dcb71bb06e07a0113039114b9fb017590cf7n/a Heodo
2020-02-07invoice MZ67_934705915.docdoc 3f4f0acca36df7acd5011cf57c593c800e02fa702bc16fc9010897858d4e819dn/a Heodo
2020-02-07invoice-J8_18448801.docdoc 3a4cf3a7eff72f050b4414552de262c441eadb589af485908e301bf678534c9en/a 
2020-02-07INVOICE-XCR460_2871105.docdoc da55d54edd3021ebaf41530e1ec8dd18fb5541bb09c3cc9d10c88e9da0351409Virustotal results 32.79% 
2020-02-07Inv FN6862_24977341.docdoc 77815318e9f6226ad493ae32d374b61c54aee323314b8bca1d0caa7ed864e56bVirustotal results 30.65% Heodo
2020-02-06INVOICE-PF8318_869880647.docdoc b45f99f3efe5bf82ee6cdee7f80ba7bbfa39f80c0973746b43efa2779a69b8d6Virustotal results 27.87% 
2020-02-06INVOICE-LJ70_749846799.docdoc a91eba1db4ddcc5437aec16814c764bd4fb7d18f221f84031177016e8e52066aVirustotal results 29.51% 
2020-02-06Inv-IFC4_677545.docdoc 4a24444820e9cbd0c73e0d97f291e4679d283f5c6fd44db547c58a37d62b4b83Virustotal results 29.03% Heodo
2020-02-06INVOICE_YQ64_8001906.docdoc af68f95640411edf06350ddc5f697fa63501dad1a427026652ba7a411e87c258n/a Heodo
2020-02-06invoice_RY0_3534487.docdoc 6c06954cbc088900ecf406f49cd3620cb6152c02121a754986fb65f7935bd043n/a Heodo
2020-02-06invoice 0734_517916.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06INVOICE-9_833500.docdoc 72cf0e1c89a577b94531a7723c3d176dfd37839c0b19bc7878c49945f7dd7339n/a Heodo
2020-02-06Invoice MZQ1_964146.docdoc b61644b4d4ea1d8856ff589c7017a16c5cb48d63a54cb1aa69aa19bfafc4dfb4n/a Heodo
2020-02-06Invoice IF6_790180662.docdoc f529e7394604d172959df3fb126f30946377ffcbed5a186bee86ce1ae13a2902Virustotal results 24.59% Heodo
2020-02-06INVOICE-P97_0000939.docdoc e10f7b95c27f399f5a1a28c5e94c61bc47ffb9f8bd9ab3bb562cf27be6460e88Virustotal results 26.23% Heodo
2020-02-06Invoice-164_80293482.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06invoice_YCB6853_73350853.docdoc 4d07b667e4701cae51210f6519e7272667622f080a5edcbec8a8102a7eb5b61dn/a 
2020-02-06Invoice-5243_964392.docdoc 12368c93f93b5feac92d01c7f620337dcbaab18dc50b27dfe2a50ebae513d355n/a 
2020-02-06Invoice-Y4787_023261.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06invoice-LOW247_427600.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06Invoice G13_98999018.docdoc 90250acf44f763164182f91d1d9e734ea442e491965e1c3883ed40fea09f0d2fn/a Heodo
2020-02-06Invoice_LHZD1024_68543475.docdoc 955266fef242bce6acb2e20a60ae98fcbe68846f196fbbabfe5304bf7c56aacbn/a Heodo
2020-02-05INVOICE_CBI8147_183062734.docdoc 23bfb58c53002a4c03a4931e057316564e8ccab64975f93e2d66ceca6c73f7afn/a Heodo
2020-02-05invoice-7532_126506009.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05INVOICE_WJW13_45681598.docdoc 2e6d60c0292605697751fd56084cb10b9ab90c135dd863bf3e428a185e050142n/a Heodo
2020-02-05INVOICE_ORZ97_40755194.docdoc 9a6d2baf1a6f63a692b3584aecb501ab9d2c4cf6cc5e97ed5390454ec60bc466Virustotal results 26.23% Heodo
2020-02-05INVOICE-XTN66_211633386.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05invoice-FNEA9700_71472741.docdoc 8376a8de56a8cd62866c0f71c3a36f91ff4af5b9d16f9056aaa8e8360af854a9n/a Heodo
2020-02-05invoice 16_307770692.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05Invoice-T1426_7844062.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo