URLhaus Database

You are currently viewing the URLhaus database entry for https://otsus.papuabaratprov.go.id/wp-admin/maint/FILE/GO2DFcL6qUME/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:699372
URL: https://otsus.papuabaratprov.go.id/wp-admin/maint/FILE/GO2DFcL6qUME/
URL Status:Offline
Host: otsus.papuabaratprov.go.id
Date added:2020-10-16 05:48:06 UTC
Last online:2020-10-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 05:50:03 UTC to owner{at}shangtel[dot]co[dot]id)
Takedown time:7 hours, 32 minutes Good (down since 2020-10-16 13:22:38 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16REP_2020_10_16_AUA22515.docdoc 5a7c0727bce9bda88cfda9cdf642a0d8e636d781c70576f32c983a9f48190bbbVirustotal results 35.48%Heodo
2020-10-16INF 2020_10_16 53376.docdoc 6a9fe9654b01f8adefb5b8869a82916c3ee7d7470eadf4f4a2fd8372163be119n/aHeodo
2020-10-165117LFV 2020_10_16 983097.docdoc 2a97f357b0df776a71ea7e36f18b4492d7e1d2b406553fbccc3e658051b2304an/aHeodo
2020-10-16FILE FZ456908.docdoc e070330805e94d235412c1d54a2c6a015bc8732679f996cc34fc03b0f9ae1bceVirustotal results 30.65%Heodo
2020-10-16Untitled 2020_10_16 523178.docdoc 1bd4395a76b6ed6c809259f58a36266882c9a3f79e1064a5ba0277561ff8addbVirustotal results 32.26%Heodo
2020-10-16Inf-20201016-HLF7591.docdoc 3858f819b8f0592d10bad163b692a1a85db0ae60bdfa91a1272c3d32f216f1efVirustotal results 32.26%Heodo
2020-10-16List_20201016_3607710.docdoc 6a089a7df35eeb01c1847b3ea416d218facf9f0a2165aff4b4fbd265b64d20abn/aHeodo
2020-10-16MES-20201016-CKO09270.docdoc 422ae15c3d269de834714e59a70f5eece8995dfe4197b56641efc28118c3f750Virustotal results 32.26%Heodo
2020-10-16Mes 517692.docdoc c5e7a769d554364fbf131980e6285aee1a4ef18fe11a28e97042d79c0422adccVirustotal results 32.79%Heodo
2020-10-16Dat-2020_10_16-112.docdoc e52f2635e68a8f40c8e47ed31a932dbd89ca5e423bc8565b71df778c2c7c2eb7Virustotal results 51.61%Heodo
2020-10-16Untitled.docdoc c7eaa50533057cbdf24f415cb8d041b1f240705fb1962b333ae94ab576f19ec3n/aHeodo