URLhaus Database

You are currently viewing the URLhaus database entry for http://pkk.cilacapkab.go.id/cgi-bin/sites/44457/WGdZlLh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:722784
URL: http://pkk.cilacapkab.go.id/cgi-bin/sites/44457/WGdZlLh/
URL Status:Offline
Host: pkk.cilacapkab.go.id
Date added:2020-10-20 09:41:06 UTC
Last online:2020-11-20 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 09:42:02 UTC to hostmaster{at}iconpln[dot]net[dot]id)
Takedown time:1 month, 0 days, 22 hours, 5 minutes Bad (down since 2020-11-20 07:47:32 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21003581623835.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo
2020-10-21Inv. 00071879.docdoc d9c9cdb661798fec5696237b21371f7bd3b1fdac360a68aa3fc3d863e1d6173aVirustotal results 32.26% Heodo
2020-10-21Copy invoice #0656.docdoc bce4a6fe31eb854ee0fc5fb9c17c81ee19922b93a2998de467fdd004aa3ddf37Virustotal results 34.04% Heodo
2020-10-21Payment.docdoc 68650e65451380320a268775d59b1d777dbfeda748e2b73807177871d912e240Virustotal results 27.87% Heodo
2020-10-21October Invoice.docdoc 28aaf240ff1f2d8e6b668c79854790eace207f11b467ea5d2479ea0520c3cce4Virustotal results 29.03% Heodo
2020-10-21Payment.docdoc e60f4878e179f0ebc8af56cc4c3c44c69f9c6ec06200644998a44c536ebdc2d7Virustotal results 34.62% Heodo
2020-10-21October Invoice.docdoc ab58608fbd277849ff1d0a208de3180f5bf8cb8773a27a0d1e833d7644503d99Virustotal results 25.81% Heodo
2020-10-21Inv_3348.docdoc 4edbef59b575a4095b13edab1b9c640b1cecc8f25a2b61f93e988285c079b488Virustotal results 25.81%Heodo
2020-10-217441384243WT.docdoc e8da9916a2da1f9ce4081c005b241bb16bae33ac6774e8fdcfe0da0d155eddbeVirustotal results 25.81%Heodo
2020-10-21PO# 10212020.docdoc db5fb70150903040a3e93dd5c87a0b442c28473d2dccb5ca3dc59c2957a243b7Virustotal results 25.00%Heodo
2020-10-21invoice.docdoc 20822d454fc7b4ccc00e84d41fcfebef444b6d243921dd0e7db0c7252f1e319bVirustotal results 25.81%Heodo
2020-10-21Payment status.docdoc b60221fbb29e77ac3d7f84dbdeaeb51c021b9072f430873d8b52f30eafcaf81cVirustotal results 26.67% Heodo
2020-10-21INV_57593.docdoc d00125dd0f069c23c0ae5f95db081c57dfd23bc67fd5308053a4204ace382b4cVirustotal results 24.59%Heodo
2020-10-21Form.docdoc cda828dede96620b0eed85c89ba9eebb9aae7aa5f6b54141207e8f0f9e44e0ebVirustotal results 28.57% Heodo
2020-10-21002016867239.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21Inv_426548.docdoc 7301eb52916c5b004b3f81ebf360c397e25aba900652108420b868313afce2aeVirustotal results 48.33%Heodo
2020-10-21OX0 invoicing.docdoc a32b8fc89045749411368894b5eb70012518a8d9d1703b940bcbc966c0e40bdfVirustotal results 50.94%Heodo
2020-10-21L-100120 CEHE-102120.docdoc 19a709ff8ecb374af7e40714b3ff541cc7753c7e69a7f0250d797356cd4ccb59Virustotal results 45.90%Heodo
2020-10-210913310403.docdoc e3812e0aa164c68399e61ce76904450c3e6bc028111a3c4df2155e37ad5d01b1Virustotal results 44.44%Heodo
2020-10-21Invoice 10412.docdoc 5ab195348086d508a9be2e1c480fa60e9de009a7f057dbaf696f8468ec4fe0f5Virustotal results 45.28%Heodo
2020-10-21Invoice #665955134.docdoc 8d8971cd4eb8a2c26f5263e44299f9f468d43614dcccdcfae564420d264e0d29Virustotal results 43.55%Heodo
2020-10-21Payment.docdoc 29cdc20b4b547e832ab1e9c0eeff5b71201efe4262d8d542a8b359131f26ed1aVirustotal results 42.31%Heodo
2020-10-21Payment.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfn/aHeodo
2020-10-21WZO-100120 GUMJ-102120.docdoc 663930eb12ff6afb8cd3d0410fcef8fa32edf4964504e10f0cd56af546b0ecb2n/aHeodo
2020-10-21invoice #11900.docdoc 470148839aa8007c61691a8cb506baef031b0bfc909e0a664bf3a94356e06208n/aHeodo
2020-10-20Form - Oct 21, 2020.docdoc d590ed65aef80ecdc7f0a44755ee436937f30c0b05287ce6d177b654512940e8Virustotal results 40.98%Heodo
2020-10-20Form.docdoc 724c5d4bb1366a1bfd8d8982ea39bc45e5943710760201cb77a7a126a4ebc56bVirustotal results 41.94%Heodo
2020-10-2005237058489.docdoc 9be377b592614918b5f4aa295f73afeb586e3e386f7bec12cf04637f31433d7bVirustotal results 40.38%Heodo
2020-10-20Payment status.docdoc 22304a354c9ba33090522b0442ccea77df12302a51a51a7901adb0db8ed5c0a6Virustotal results 40.00%Heodo
2020-10-20invoice #43919.docdoc 44e883c1fa7e5fb65b33f89f1705f6f6ffad48cd9113a845a7bf929b7f3a8b0dVirustotal results 35.85%Heodo
2020-10-20RA1298520001BO.docdoc 864eeb47c83f4648f5c3a22de6c34559c24f871adfe7490af5c932ee7fbd52f4Virustotal results 32.26%Heodo
2020-10-20LZ-100120 NXQZ-102020.docdoc 80112c9d5f76aa1687aa0df70c0d7f1d96f1b7524da942b87480ff37231091e8Virustotal results 32.79%Heodo
2020-10-20Z000 invoicing.docdoc 1949d127f8cad19649adb5f4534e1b6eff752a31d5ea73e427d0ef8c90511ceeVirustotal results 32.26%Heodo
2020-10-20invoices 91710 & 58061.docdoc 15e191fa2be80a5d0b1b3af67b1ed360c006e3634442bb6255e4cc0f901abcd3Virustotal results 32.26%Heodo
2020-10-20Payment status.docdoc 2edd7b8840ae58ec73ff6cbcb1977e99a4acd696f46234e98cd42e9d6f9df365Virustotal results 32.26% Heodo
2020-10-20Payment status.docdoc 3bc3a1ea24bd194a23d6c8493b9754de9a41127025a14052754eba04dd1dda70Virustotal results 33.96% Heodo
2020-10-20FR036 invoicing.docdoc d725a9584594c0da62483ec85e99ce8baa89ab5be45320176bb3576abddcabe9Virustotal results 29.82% Heodo
2020-10-20October invoice.docdoc 125f1d5c057389effdcea5d909bfffd9749d79c9a1370a3e057d777bae4bc1f8Virustotal results 31.03% Heodo
2020-10-20PO# 10202020.docdoc 61835e08172767d73a9e6c5dfb1fcc8b904d60c3b9cd7b382bcfe43aeab5c2c0Virustotal results 30.00% Heodo
2020-10-20Invoice #97086311.docdoc e5aa196851c5aeaf14159523ad237116ee42b2f0ff9b950949ec77eef8b6247eVirustotal results 34.62% Heodo
2020-10-2000324469127.docdoc 4217ed123cc2bd063b8cc599340aec39fda437a4e62df3118a01251a915c226bVirustotal results 34.62% Heodo
2020-10-20invoice #8810.docdoc 18286f51c980997e07241a170822a950f101cfa264c232edbfcb4d67694d5b45Virustotal results 31.15% Heodo
2020-10-20Q00974 invoicing.docdoc c7bae32f76eebe4cb2fdbd687d6d09d30ea38d1c6751a1ae5cbee6c9bfb5b96dVirustotal results 30.00% Heodo
2020-10-20invoice.docdoc 589c7b11cb037b2183fcee493e98930358a15693532b1340c7f4cf1d2f50c636Virustotal results 32.20% Heodo
2020-10-202102058.docdoc 0c826456d4bf7da7aaf36377a19de56cb2712b94c047a86518ff7745d252479cVirustotal results 32.26% Heodo
2020-10-20Payment.docdoc 47914da6e4ee4b6892b42cdb0076cc23a9887a862a7b366434d7c77c0a21123dVirustotal results 32.26% Heodo
2020-10-20invoice.docdoc 8bec43e2d05761c02be362fef3cf9b6f0f4963f122c275c7c7686e3cea6fd5b1Virustotal results 51.61% Heodo
2020-10-20PO# 10202020.docdoc 2f0abbe89ce350352b4029575dffb4895f42d2296aadc1745287763704b7093dVirustotal results 51.67% Heodo
2020-10-20invoices 59027 & 82858.docdoc c31795e9d2a3b7bf6e19d054a2574f0ea3eef997e49bd9318316efd609cada94Virustotal results 50.00% Heodo
2020-10-20Invoice #129698.docdoc 5cfa1457e7ddb2e7c49419cabef1c969debc4d677e7ca6f72d6edd8e2ac88a32Virustotal results 49.09% Heodo
2020-10-20Z016 invoicing.docdoc 9fdb062ded6d82fd2d2d452643f3eccce639b07b20b205b0ce7cb8ceb31ac487Virustotal results 50.00% Heodo
2020-10-20Payment.docdoc 60ac2df8c0a56c198ce34633dc5af133c4fda800a85383a2ea9e6da298e77904Virustotal results 48.21% Heodo
2020-10-20form.docdoc 31c9941b5e674b482e7b5020bce1c27dd86c8529fe254326dcd4a86d137492e1n/a Heodo
2020-10-20B0059 invoicing.docdoc a67d3d825a05eae828eb68703949b29ce211f2873a8c91c7875b89ea9577a817Virustotal results 49.06% Heodo
2020-10-20Payment status.docdoc 9274f1cccd6ac0af51801682a093404e9f2f3453120e01d07f4e2086d73606eeVirustotal results 50.00% Heodo
2020-10-201194700418GL.docdoc 9dead7615c9982a5935592ea257a1c754b61ee79c39b61345ce30c18e1756cb2Virustotal results 50.94% Heodo
2020-10-20Inv_44556.docdoc 1d6ddacfa157c7a54a7f33fc1f1941a643a4a4f799268d4f2fdb333e4d6d49a4Virustotal results 49.18% Heodo