URLhaus Database

You are currently viewing the URLhaus database entry for http://urbane.co.id/web_dev/closed-sector/corporate-space/myhfs3y3yr-212311t0y8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433276
URL: http://urbane.co.id/web_dev/closed-sector/corporate-space/myhfs3y3yr-212311t0y8/
URL Status:Offline
Host: urbane.co.id
Date added:2020-08-14 14:15:37 UTC
Last online:2020-08-15 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-14 14:16:02 UTC to abuse{at}phoenixnap[dot]com)
Takedown time:12 hours, 18 minutes Good (down since 2020-08-15 02:34:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15rep_20200815_S8704.docdoc 1734600511f94a2370e03e5367dd885e52858cbef41ea6d3e06ca06370573260Virustotal results 38.98%Heodo
2020-08-15mes_2020_08_15_P536001.docdoc 64d7da61bc5e477dcd94a4ec0bb3d8c5b2a8047f4118704f2e7be561cf217b0eVirustotal results 42.11%Heodo
2020-08-15List 20200815 72726.docdoc 4e43c1bccc2a042dc04313c13767fe7198126d875df525d57496e7b75453261cVirustotal results 40.68%Heodo
2020-08-14dat 20200815 F83279.docdoc d07ec4fc9657ea145484957e5b68242e719e4a327f4f1c7b1fe940ae182fdc84Virustotal results 38.33%Heodo
2020-08-14Doc_2020_08_15_VNZ1492.docdoc 9517fc7b84b22b3d4f23e53877062e2d46f1491e927b91eea03a9f3fe2dc5571Virustotal results 38.98%Heodo
2020-08-14Dat 20200815 D52434.docdoc f646aeaff883c64577b9a0c190d5e020f5278ad21bfbe9a2192850c5e201bf93n/aHeodo
2020-08-14inf_YQ91104.docdoc e3cfaefd87b2aa287ac22562cc177ec6744c3c9ac27db58b5d2bb7625b694d3dVirustotal results 38.60%Heodo
2020-08-14Mes FDR8431.docdoc 47bdaea6a07bb610606749e17a9bab9ef95c161454b2c782d5cf1dc2b3b63a45Virustotal results 37.93%Heodo
2020-08-14list 2020_08_14 H52188.docdoc 0329d83d9949588804bf1615b60d92ce249db4cf10f1e177992923891e6c3218Virustotal results 37.29%Heodo
2020-08-14file_2020_08_14_PK5923.docdoc 665456af44fc843e545d1937baeefa7a85f67eaf4b0c1254adf627ceb4024372Virustotal results 38.98%Heodo
2020-08-14rep-2020_08_14-QXM12615.docdoc c74d9497f6e45b986c8d3aa90e037e0bdf572731082d874ca8187cd51fd90486Virustotal results 37.93%Heodo
2020-08-14MES_2020_08_14_9127399.docdoc e152d1f85c44b4da187ff4297ebf427697578fb0789379eac2149b19b006813eVirustotal results 39.66%Heodo
2020-08-14doc 4813837.docdoc 162582c2350c22d014b738bdea37a87272c1bb3ce559c38796b0b850f2c184f3Virustotal results 39.66%Heodo
2020-08-14Rep V387278.docdoc 6a0fbbaaea608bc615282f654c37b65a1ae6521dd8734366aaeb902d4fb7a969Virustotal results 39.34%Heodo
2020-08-14MES-20200814-1559175.docdoc 0d01a7fdccf93dc8175ced2abd4e77c377c633003dce71e12fe488214c5c5a6dVirustotal results 33.90%Heodo
2020-08-14Mes.docdoc 42ff2736d6bea5f31eaa0cf531bf67861730ec192bd418caf52c3346eaab02a3Virustotal results 31.67%Heodo
2020-08-14List 20200814 XRZ97801.docdoc a675c1f8716e8abbf91707c8dac69b2d16c14ea7177a8fabb92c4061b65dda9dn/aHeodo
2020-08-14rep 20200814 JA949750.docdoc d7d0bc90406ac2e4110cb71bf2793bff657e01d0a25b48944bfa75e14855f84dVirustotal results 30.00%Heodo
2020-08-14doc 20200814 3670566.docdoc f8d9aeff9c3ce77dae1ba129171de9f937a96e0b2428800091c0336bd58ee6a0Virustotal results 28.33%Heodo