URLhaus Database

You are currently viewing the URLhaus database entry for http://smkn48jkt.sch.id/wp-admin/statement/6q200qo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:704137
URL: http://smkn48jkt.sch.id/wp-admin/statement/6q200qo/
URL Status:Offline
Host: smkn48jkt.sch.id
Date added:2020-10-16 21:42:07 UTC
Last online:2020-10-17 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 21:44:53 UTC to abuse{at}hetzner[dot]com)
Takedown time:5 hours, 8 minutes Good (down since 2020-10-17 02:53:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17INV_HA4673619473NZ.docdoc 02730b23749bb5e945d78771425520fe94a15b5647f34a7efeca54a72c9297c9n/aHeodo
2020-10-178TMHOGVYSLH.docdoc db234da6bba5f671c8a6fad07cfc6ad7ce1b078a32f920e2edb4b142167e18dcVirustotal results 51.61%Heodo
2020-10-17DOC_QP2028228637IN.docdoc fd0ec2733cb7fc4d8f934cf81b56a9a6fd2dd7290c257cdf4c2a1b3da2bcfc10n/aHeodo
2020-10-17BAL_PO_10172020EX.docdoc 4f6043ed53481592c3b9db4608a157df568b466062cba2018b8e5c59bfb40563Virustotal results 52.46%Heodo
2020-10-17JLR_100120_BXM_101720.docdoc 72bc6543f22de398e1374caed638e9a1d24ec0b37a5fa9b5ac10ade7559ab839Virustotal results 50.00%Heodo
2020-10-17REP_QQWLEXHZTTTTQ05.docdoc c40e490d1149a43b982a7c65d5f04d36117a86623374f75bf8d47f31090f8b18Virustotal results 50.00%Heodo
2020-10-16REP_PO_10172020EX.docdoc 3bae78182dad47ac43920171f44e275863e25a8cbdd07ac0b0279edb751dd12aVirustotal results 50.00%Heodo
2020-10-16X_QO4931820308XE.docdoc 53467ef76cb2d0f4cc9404439089220dd6d34680c167f2f062307713724ee9bbn/aHeodo
2020-10-16REP_JR6419232576AX.docdoc 34470931a684a070f70a0ed741a36c388fb0c082426aebf15aeedbc28a4d778bVirustotal results 53.33%Heodo
2020-10-16INV_XML_100120_TJV_101720.docdoc 39dced6aa4d3785efffcddc9b87bb1744c386d811cf509ac1baef383eb0c38cen/aHeodo
2020-10-16D_MAC_100120_TGT_101720.docdoc dae05fe983f37d53c614de68c40f3da714bccb7dd377adecaf6a7592c31cdc4bn/aHeodo
2020-10-16DOC_76195995.docdoc 7bc4797a66cfb8dbdc6f95c5568595d0229200838644a798b7228d1bde86b554Virustotal results 46.77%Heodo