URLhaus Database

You are currently viewing the URLhaus database entry for http://disdik.barrukab.go.id/wp-content/DOC/ht4ar5OZU8ID5b95xfg8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:704633
URL: http://disdik.barrukab.go.id/wp-content/DOC/ht4ar5OZU8ID5b95xfg8/
URL Status:Offline
Host: disdik.barrukab.go.id
Date added:2020-10-16 23:51:05 UTC
Last online:2020-11-04 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 23:52:02 UTC to hostmaster{at}indosat[dot]com)
Takedown time:18 days, 9 hours, 52 minutes Bad (down since 2020-11-04 09:44:48 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17mes 6566763.docdoc 294c6f87d8514072c30988bd55dd643c5c018b9f9ae05b9db1a97d034b31e092Virustotal results 55.00%Heodo
2020-10-17Inf_32199.docdoc fd4a45974318a540bf249d7aa768f6d4ec1bb268bb05e5028935db34aff711f4n/aHeodo
2020-10-17Rep-20201017-FJH0707.docdoc cbabf68dbf69bbc9e13cf1c4decc549416db53379348b45da4b5fedff65152afn/aHeodo
2020-10-17Inf_20201017_C096.docdoc 8763a9868e952dfb5be76162ed10b0d62fa00e1ba5baebe53f7cca486cb89542Virustotal results 53.23%Heodo
2020-10-17Dat 20201017 8451.docdoc adbad3c068d4497ae8a6a18056cfc39fb152c2085f694dcace8e772cc1867f22n/aHeodo
2020-10-17arc 2020_10_17 DT990.docdoc c8647133e45a641a9cefb6726994df00dcfc9fa481d38e667eab8f74f75c54b0n/aHeodo
2020-10-17LIST.docdoc 971e189c279099a876618c3226ef35e5afc62b91daf3b8bde466a424fdfaa063n/aHeodo
2020-10-17Mes 2020_10_17 Q16554.docdoc 4885a6fe3e6e3cf17f4b9c157b848115b2b51fc4b8e3e478650c6d8401062476Virustotal results 51.61%Heodo
2020-10-17doc-2020_10_17-MCT486.docdoc 78f2969b92269cd9a3e1cc7003b0949f47421d551c323dbeafa94ad0a836bf34n/aHeodo
2020-10-17List-I1342.docdoc 674b59aa10f963845214c91833225375d26e69ccece07609e8a5425a8d952346n/aHeodo
2020-10-17Inf_20201017_D954782.docdoc 4d8d65bde63051b5066a4f7aa37942fbd309a54311e5b0903febd4d1277be363Virustotal results 51.61%Heodo
2020-10-17Untitled-CLS576234.docdoc 16d3671dce46d1ed5c56603f8cad5b0b5a78ead6e605081d2ffffcbfe266b15dn/aHeodo
2020-10-17INF-AI450159.docdoc 65fe5c36c465cfa1cc58f54aca29a2da9e56f3fa0b499ff8ae0b654338db114bn/aHeodo
2020-10-16REP-2020_10_17.docdoc a9d9b8357ff803bd36d7bd0c12c770487fe774ccd22e81318606bad0f6ddaf90n/aHeodo