URLhaus Database

You are currently viewing the URLhaus database entry for http://dpmptsptk.barrukab.go.id/wp-content/esp/hxcgzz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:704605
URL: http://dpmptsptk.barrukab.go.id/wp-content/esp/hxcgzz/
URL Status:Offline
Host: dpmptsptk.barrukab.go.id
Date added:2020-10-16 23:45:08 UTC
Last online:2020-11-05 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 23:46:02 UTC to hostmaster{at}indosat[dot]com)
Takedown time:19 days, 21 hours, 1 minutes Bad (down since 2020-11-05 20:47:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17DOC_JP46U2PLXXW78C.docdoc 360a5cb7eed923017b4ef07460e7652362cdf1fc0a902516addbb8e244e30134Virustotal results 54.10%Heodo
2020-10-17BAL_PO_10172020EX.docdoc 39ba6406fa7f104c5275ad449ef4bf5f319caf7089cf553da10dc8ac12387f18Virustotal results 52.46%Heodo
2020-10-17INV_985156763005.docdoc b0f945ed6afda303421f9501b2b2d1d2996a132eb27486911019cb9996538460Virustotal results 54.10%Heodo
2020-10-17GAB_100120_GGT_101720.docdoc c5b951c65f67f1136dedc670dfa0cf0fe59abb9172a0fe5a6011e2882e129e8an/aHeodo
2020-10-17RJK_FKCS0FRUWIUW.docdoc c309ac7c5bd891429998c87f40086ae669e29affaa99e133c557fbb78bfa269dn/aHeodo
2020-10-17IWY_85754436.docdoc fa3c245c0bfe5a4b95d229481cbdac5dc3798f1948badeecb3dc692f589c5f7fVirustotal results 53.23%Heodo
2020-10-17PO_10172020EX.docdoc 2b95f52b2f665277c1b271f68b7ac017b7653d398e73877b7c8db4bf2ccaa52cVirustotal results 53.23%Heodo
2020-10-17VY_TME_100120_GWB_101720.docdoc 67d27bed76861586613fbc785b6d089a2e01fd18bab5219bbe4df011e29f711fVirustotal results 53.23%Heodo
2020-10-17PO_10172020EX.docdoc ff9996026d66c80170010bab3d84d0ba1ecac3a6b87f8e694008feb0bc0b3d4fVirustotal results 53.23%Heodo
2020-10-17FILE_285864055719277678285.docdoc bf7d2c74845e2e6006ed753d93f64d23813dba57c4f443be01f59915f96aaca4Virustotal results 53.23%Heodo
2020-10-17INV_PO_10172020EX.docdoc a9c15187e473446421b0e900dcd094ee8be1c5ac010d6d2a19bcc988f60d7ddbn/aHeodo
2020-10-176AF94NWOAY1S.docdoc 82886986ef5507c85b6e17a8904a70bb3b67212863f5f835fa7bc3392d070f80Virustotal results 53.23%Heodo
2020-10-179HHY0VAMC1.docdoc 7f7aaae8116f26c7d91c5c3d87ab7c7a752e628195c25563cc7c3074669e6c7aVirustotal results 54.84%Heodo
2020-10-17INV_05507936.docdoc 6d5ed047cba0f40a2bd108fdb285520a5590c29ac64b7a9d32a20719905f1e7cVirustotal results 53.23%Heodo
2020-10-17INV_GMI_100120_PBF_101720.docdoc 920a210b924453a21c734f46a853d5eefb835b8f7e33cc3402355037771648c6n/aHeodo
2020-10-171557758526.docdoc 4f1b55b5cbbaa28b0d87b93dd256cebd16df18a51e081378940ad152fd24da8eVirustotal results 50.82%Heodo
2020-10-17FILE_IV2041115549EK.docdoc 7563b098e425087d70e59bc0ad1d712d39ec6286fc63eaa9a9eea68f9a7ede26Virustotal results 51.61%Heodo
2020-10-1754802338951905740.docdoc 252e05a52d4bc9d3d266533b1a75bfab674989b8d3a4f0ff8d898529379329afVirustotal results 51.61%Heodo
2020-10-17REP_5PMP3QKW.docdoc d1e952f7b8eac274a9eb54c0ce6e8c6542aaa16cbdf7345c10c79852c2d5bd0dVirustotal results 53.23%Heodo
2020-10-17INV_PO_10172020EX.docdoc d19c1e922354570a8700f8dc25900a7c8ae4bee4b08908a4c6cad2309eff1ba1Virustotal results 51.61%Heodo
2020-10-171160128613.docdoc 61cf4ff84de3e35dd24e8df00464aa832912b8c378cbffc5da91abc576c809fdn/aHeodo
2020-10-174620628401122274919891841.docdoc db234da6bba5f671c8a6fad07cfc6ad7ce1b078a32f920e2edb4b142167e18dcVirustotal results 51.61%Heodo
2020-10-17INV_ABM_100120_VID_101720.docdoc eb06448eea7b0d73132945671275ea572688e13de195a89974d8315900ff8cb7Virustotal results 49.18%Heodo
2020-10-17JO6KQOI.docdoc 5990f98a0aeffb24181deb144a8519e54f7695794e545b9ba0cb52fe28e3f987Virustotal results 50.00%Heodo
2020-10-17FILE_HJE_100120_PVJ_101720.docdoc 99acccb026919eac0d3249c8a9207a71d032fbe59c7540c12aee398ae86e6780Virustotal results 50.00%Heodo
2020-10-17JYAJ_DB7608172087UK.docdoc 1f9fcb8ad3585c6cbf7250308fc58ebd7fd913baf350cbd3d7fd8934c9e33e43n/aHeodo
2020-10-16INV_49341015754931868584.docdoc 3bae78182dad47ac43920171f44e275863e25a8cbdd07ac0b0279edb751dd12aVirustotal results 50.00%Heodo