URLhaus Database

You are currently viewing the URLhaus database entry for http://metrooptik-bogor.com/cgi-bin/browse/8wVLYYrKW2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:625296
URL: http://metrooptik-bogor.com/cgi-bin/browse/8wVLYYrKW2/
URL Status:Offline
Host: metrooptik-bogor.com
Date added:2020-09-29 22:19:21 UTC
Last online:2020-10-01 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 22:20:05 UTC to abuse{at}deneva[dot]co[dot]id)
Takedown time:1 day, 4 hours, 20 minutes Poor (down since 2020-10-01 02:40:09 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-01Attachment_20200930_09679.docdoc 473ec3d3fde59b60a77bd40a859211f5453ec5d08bb02c1fde40b56bf07dbbe2Virustotal results 27.87%Heodo
2020-09-30Rep_20200930_CN431732.docdoc b808848ee2248193b0a608d6285ec7c1978405f2732a86fb5d05dabbc794fcf1n/aHeodo
2020-09-30UNTITLED_CB05528.docdoc 45e1f883fdc6cad4f635eaef749c53e835d79fc175cc58e46113473d6c93d76bn/aHeodo
2020-09-30mes 422266.docdoc c69355e7d2f37fb8a04b2808e24c6abe076f296b1063e2fa5eadb435d4105da3Virustotal results 22.58%Heodo
2020-09-30Rep-20200930-VGS7091.docdoc a2f068e639e0e1515aac78229f989b527b32f69b8ae74701bef79fbd4dd20b6fn/aHeodo
2020-09-30Arc_20200930.docdoc 028661b4068147b441bb85f54020e1a03290adf9a56a2fe4407e68509ec7a812n/aHeodo
2020-09-30Arc-4555527.docdoc 88b3cbf0d3014e9fc3a1a67822f9ecdfe4524c239d65cbaac6cade063e875415Virustotal results 22.95%Heodo
2020-09-30UNTITLED_43581.docdoc ccd09c9d5a3e23cf11d4573a5ce8d84c634f8cdcf7188378a94ab61d27544009n/aHeodo
2020-09-30UNTITLED-053.docdoc ed926a7382b4d41f66e856dd4a63fb1999014f79f63cbe3c57deec6b6a79705fn/aHeodo
2020-09-30Attachments_2020_09_30_CMK0445.docdoc e5f595a826309d1309411963281babb3e9d29b8149a7f105059242d22a207863n/aHeodo
2020-09-306813ALY-2020_09_30-Y92139.docdoc 4ebff15117e2aee0ae124e202b18a7ea9fbcd113a26f227177306daf71103ea1Virustotal results 24.59%Heodo
2020-09-30doc-LG267.docdoc 85247823ff78f679302c4390b3fa30ff8fb4f6ed53ea662d3caec79013219200n/aHeodo
2020-09-30Untitled_80890.docdoc ec9d596dea9e8934a188f8d65b878a79dd49654e8159980d96eadf857e90cf7en/aHeodo
2020-09-30arc 2020_09_30 WC4790.docdoc 93a2ed7a78170e133dbdbd922f75c779845602ee85fd0af76b5550640ec8accdn/aHeodo
2020-09-30DAT-926.docdoc fd826f7ad1f1e372efdc57065d0bb9c4c29931529a7ec64c0cdc3fce95a4b547n/aHeodo
2020-09-30UNTITLED-2020_09_30-367754.docdoc 925b00d3b7c0de40772e08eac5e84478d63382cae3b40124e9e5e3e8157f7c5fn/aHeodo
2020-09-30UNTITLED 20200930 8877.docdoc 228ffce29f71bbbc7b5acb1a7c6f505c27fa73316d854099493f88a8af91a73aVirustotal results 23.33%Heodo
2020-09-30File 2020_09_30 SE1639.docdoc 5bf5490d9daa5f884b6597377c8d3f4200a86f12a88c613b3b633681f3998191n/aHeodo
2020-09-30LIST_589.docdoc 1d5392f655dcdc6f812366e57505b4f345c53a8c5ede33a7f7b9d6e05c3deaefVirustotal results 32.26%Heodo
2020-09-29Doc-20200930-068.docdoc e4deca4ef3c529f48c73898860d8b4922d67b934f7a168de5212f747a16ac0c1n/a Heodo
2020-09-29UNTITLED-20200930-S00474.docdoc 44deee00b7451801d4a17c257ab6e48d119efdd78dcbed03daf5cfeb20a84b51Virustotal results 30.65%Heodo
2020-09-29ARC.docdoc 1c66d607d768fda8908683a9139ba103d12f44f588c622dace25ea46c28f9945n/a Heodo
2020-09-29mes_20200930_4592711.docdoc 2ce2a7979c53158a0e7454224e6755704290a5a16a092aec69088da9eb3571a3n/aHeodo
2020-09-29FILE-944504.docdoc b6924c37febb8c64ef7ba11d8266e713aac4062636eb088d498cb095fb68010fVirustotal results 19.67%Heodo
2020-09-29FILE_20200930_106.docdoc 48ebe336fa3c33ff63a0c39c304a9c707bca857dc12cc26343602e088ec7dd18Virustotal results 19.35%Heodo