URLhaus Database

You are currently viewing the URLhaus database entry for http://tourgunungkidul.com/js/Document/XYzH5xs4k7tdK2a/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:542013
URL: http://tourgunungkidul.com/js/Document/XYzH5xs4k7tdK2a/
URL Status:Offline
Host: tourgunungkidul.com
Date added:2020-09-17 06:29:38 UTC
Last online:2020-09-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 07:46:03 UTC to abuse{at}jlm[dot]net[dot]id)
Takedown time:10 days, 9 hours, 50 minutes Bad (down since 2020-09-27 17:36:17 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19List_2020_09_19_DIS831560.docdoc 9f038a3f8faa7d88948648de22b5ab1fdd3cc1d598fc1125ff950daa9fadc4b1n/aHeodo
2020-09-19INF 2020_09_19.docdoc 1f4636599b3de756ee92e6c14346ceabf27b76d2b45abe64d1d9f48f0e4c3bf9n/aHeodo
2020-09-18Attachment_685.docdoc 000dd08101567f408a0ee2b7d095d3baa02f532ed3839f66b60b9d64ce065d17Virustotal results 22.41%Heodo
2020-09-17Attachments 2020_09_18.docdoc 7e471a0df104975c9e269668322c7a09a6892fc3a375150e2c8b0eef6b7b6f23n/aHeodo
2020-09-17LIST 2020_09_18 5538523.docdoc a33042b095d430bf74b7e603415bab7b4b48979dbed37a7fc2c51a39a0beca08n/aHeodo
2020-09-17Attachment_20200918_NQN1242.docdoc 4570e5d2c1356c0ea7261e02960c106cb8b111ad69a1f6e4c2d312ea21093df4Virustotal results 35.00%Heodo
2020-09-17LIST_20200918_HKY8489.docdoc 2a17a0bcb3ed1f0bbc6df20f64db1e8c7cfef71e891012fa303ab3bc0de7b0f4Virustotal results 34.48%Heodo
2020-09-17ARC_2020_09_18_554769.docdoc 850576cea8a5bb3ce74dc5287f0f8c9adc2e80fe5c724430473342010405ae4fVirustotal results 32.20%Heodo
2020-09-17Untitled-2020_09_18-J3015.docdoc af71dba4aedc710e31ef8c60998f0efcaeaebf52ef6ded2857f81257f50b41adVirustotal results 33.90%Heodo
2020-09-17FILE_20200917_14713.docdoc 7a7facaf5ee1b9709ccc3bb2b8188ee0307b2a7be7e97cead7fdb9c02d232752n/aHeodo
2020-09-17F07728.docdoc ba0c0591a4c66d1df253cb44649bdd2a14903ea5fda1161df9e1aaf10242d9b1Virustotal results 32.20%Heodo
2020-09-17doc 2020_09_17 XZE57478.docdoc 365353a8c4daf08b6b1ac9baacd65fbc835475a6e165996df62abdfe1f218d60Virustotal results 32.20%Heodo
2020-09-17LIST_2020_09_17_6726328.docdoc f86a5fb18dcfc72a906b7458e223f40121d3d51049448370f73340890cf89993Virustotal results 36.21%Heodo
2020-09-17LIST_2020_09_17_RVV3172.docdoc bb9d0e9047a36016202046098d19b5d610686d981482a95ddd10c3ff06bbd3d5Virustotal results 30.51%Heodo
2020-09-17Mes T8026.docdoc 98632e96b70d38ce6029a1216a0bac4b571db57e8cdc5c727fcbb67eb88cc439n/aHeodo
2020-09-17List_20200917_0976.docdoc fb5fff7878856cd2289cf8e0f9cc0f6f8ca84d0945a229a1d94dae877518f3a1n/aHeodo
2020-09-17Rep 4203.docdoc 87ded30e3ef6563b9027510c19fcb3b8893f48503ff9fc715d14c1fc049c0b14n/aHeodo
2020-09-17INF_20200917_8955.docdoc 1583ff2b2aa0f561381343773c8693a1a1e0f08896fc5c2f8d2aa182e77f3cb6n/aHeodo
2020-09-17Mes IU0378.docdoc e28b9264ec1942c7107b3ccf9259d754b9892e28eb458349bcabc8946b0c15e1Virustotal results 31.03%Heodo
2020-09-17doc 20200917 Q170.docdoc 159d9695cba782d8b0504fda172db4b5d668b77a9b6673acdc7ead7afccb3f45Virustotal results 30.51%Heodo
2020-09-17Mes_34921.docdoc c023bcc7ccee93b4f5b3fb912d8bfc4168078e9b608d21de57de7c3f6898cafdVirustotal results 30.51%Heodo