URLhaus Database

You are currently viewing the URLhaus database entry for https://ics.co.id/cgi-bin/invoice/2sxopjo5buz/1leypkb4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:724383
URL: https://ics.co.id/cgi-bin/invoice/2sxopjo5buz/1leypkb4/
URL Status:Offline
Host: ics.co.id
Date added:2020-10-20 16:13:07 UTC
Last online:2020-10-24 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 16:14:04 UTC to abuse{at}pc24[dot]net[dot]id)
Takedown time:3 days, 9 hours, 20 minutes Bad (down since 2020-10-24 01:34:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21WUG710B2XVA7O5.docdoc 7606c587c9a22687f99deb394aedd9be63d066c53c44d9cb78dc3a03319f670cVirustotal results 29.51%Heodo
2020-10-21AR_6266187323964192216708.docdoc 8a2b904ad14790b5a69146c0f573dc2da8adc472159bba2aed0afdfe0a550d5fVirustotal results 27.42%Heodo
2020-10-21I_2405996179956097.docdoc 02a8230dfddee28c717cc288e1573b5a44194cebefd65b8a20d0e37e2e086a1an/aHeodo
2020-10-21INV_3024965962680142.docdoc f168ef97aa8cb399a6f327fb6a301f7ae5e115c7ed1ad5c8b59819663bebd7e2n/aHeodo
2020-10-21A_PO_10212020EX.docdoc d2a68a5159ea637fa9428d39a0d9469c6c2db0b16b2de2593070c17a0ad49520n/aHeodo
2020-10-21JVZ_100120_YWT_102120.docdoc fe647619aa21d737e9f948fb92a9286a5f03bac06ab881535069fe060bfd622cVirustotal results 33.87%Heodo
2020-10-21BAL_PO_10212020EX.docdoc abd94a7b58ada746b22d9d6a4ef2b3847deda4d5569325459951c0c7f3b2a355Virustotal results 33.96%Heodo
2020-10-21FILE_935554622673309596951.docdoc cdf08877df82aef07518f10414f3dc1ec0bca6a662ee6191b7c76105bb51a0b1Virustotal results 31.15%Heodo
2020-10-21DXC_100120_DIS_102120.docdoc f762fa2e19b39567f9550fec095e6bf1f7655fee2bfa11190f293736f74f57b5n/aHeodo
2020-10-21DOC_317953712.docdoc ce72abdb386adab53d71d068388c21107144e7d9c1acfa2f898d0ce6d7b2acefn/aHeodo
2020-10-21831252405.docdoc fe15277e67a0613b3d95b606ce70df9644eda15dbf383f2523d089ba239fead9n/aHeodo
2020-10-21N_01579283889462296305.docdoc 64c0402c0b906a218b1e4c2101145066a57b5a034a16a82957081f8ca15b4763Virustotal results 32.08%Heodo
2020-10-211990732271964252057553667.docdoc d6edabb30c96ad35f08d16e274d639b6a5a5208e7b35167d56392a44b3842599Virustotal results 27.42%Heodo
2020-10-21FILE_09937734.docdoc a3b816362471dd5502a7f46f5dc0bdab4ecfff681f06c9aab0d9e227ec535faen/aHeodo
2020-10-21BAL_WD7127131947EA.docdoc 71e55ad14abd213d5627b65f8f045b2c9337c629a556868c692376c331d9fa58n/aHeodo
2020-10-21BAL_PO_10212020EX.docdoc 14db2954827c22a1f16b0326dc0d7443d94cd16d6bc7da92a933e19e64a34fdbVirustotal results 50.82%Heodo
2020-10-2179410128.docdoc af36ad567085faaef5425d233641e227fdf842e426001e855103b942dde705efVirustotal results 46.55%Heodo
2020-10-2133297781109842.docdoc 71c25e3712abdd3d405b0a43f2819fb51d16dd9bf3c5fd5c9ecd04b028240533Virustotal results 47.54%Heodo
2020-10-21QB4041365300ED.docdoc 99e0cc7017a32fc566d969c88fae5cc8db236858e93bfe804e18a1c4a08e94e8Virustotal results 50.00%Heodo
2020-10-21FILE_PO_10212020EX.docdoc 850a811a1e29aafadeaca369778609e35c77edcb8588f69f153e44195d40d6b5n/aHeodo
2020-10-21BAL_AP6826894210CK.docdoc b886042bae6dcbb3ff1e2343630f7c873d2fedbc6b59147c40346b16f69c8603n/aHeodo
2020-10-21FILE_81133136.docdoc 1c69c8db95ce9e60d2cd1b61601b96a3a5bca68602f2da10fb5cbcfd2e354401Virustotal results 37.74%Heodo
2020-10-21REP_11KD976PLADX63.docdoc 844d9efee04baab149ff86c31963c101151796f861eb84cd816fde655e3f7f78Virustotal results 39.34%Heodo
2020-10-21FILE_9871268479985468777697823.docdoc 192d1f4fdc36c10af1e2e207ca659c5b7549c01b189257a12f226c42a6c6b4cfn/aHeodo
2020-10-21INV_PO_10212020EX.docdoc fe1e5c66a4990cc515e5925db68def9f29f1893d9c6d3fa6b47e05f5c5f618ddVirustotal results 46.55%Heodo
2020-10-21GVU_100120_YIM_102120.docdoc d8d4feb29b46ade146a7b8343070d2a975e4b0e186ca6aac31ea941e46a7af73Virustotal results 46.67%Heodo
2020-10-21DOC_M5HNPGFG.docdoc 927877d8e5e4459c44bb91a386050f2aee647421c37048212690b5caa0fba080Virustotal results 48.39%Heodo
2020-10-21DOC_01177253.docdoc a22d83a786eb7f5a04facaabb04117ecb5f8cdf09fcbb8405c0a70c97a51f225n/aHeodo
2020-10-21DOC_PO_10212020EX.docdoc 730dc7281140bb144e159ad27638ff4f4d3a021999727a26b7731250343a3f76n/aHeodo
2020-10-21EUJ_100120_KNM_102120.docdoc 614bbd10017422522d46a734ed08de066834e449d5802b036b0231a39b0c043cVirustotal results 34.78%Heodo
2020-10-21Z_SKZ_100120_RLR_102120.docdoc afcfe7ff49c2df7f47347c4c49d64ac3f027b1c79f5d090a0daf526fd65d859dVirustotal results 41.67%Heodo
2020-10-21DOC_EJH_100120_PZW_102120.docdoc 8db61b871aac2949105b26c1ca2a22579e3b3d6e99aab20279c3bbea5dc87b8bn/aHeodo
2020-10-21EUNQWDUUJ.docdoc 89e10dbffeb48b429f49468630b9b93f988c4ca3e6a7de17367b398447309bfen/aHeodo
2020-10-21DOC_NHZ_100120_TTL_102120.docdoc 7b59e4314d2b1bbefd045815d54be5bd19315bcd13e3de6816a36bfd0930e032n/aHeodo
2020-10-21DVW_9ROLJCBGACE.docdoc cd0c0ee5979ebfa7ed73a40ee1f879f2b65cc57ed38619fc4f7e186c15e54128Virustotal results 38.89% Heodo
2020-10-20INV_PO_10212020EX.docdoc 681fa75f785a2b6eede8e0045ce0ba666fc0be736b8bba8d23f474b0bc400a7fVirustotal results 39.62%Heodo
2020-10-20BFM_100120_NVN_102020.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 44.64%Heodo
2020-10-20INV_0127119502982281079558.docdoc 549072b3e94570b866d20997383d99b1b2a7b9a014cd41ab974cb0853307058fn/aHeodo
2020-10-20F_BR2752968698ZG.docdoc bcdb89d7d2d271835e7e1ceff879417bb8a1f2fca4c85f072c93144e846b39a7Virustotal results 45.90%Heodo
2020-10-20INV_13930156.docdoc 0cc0e53f93e28f521e6741dd09848e105ecaa03babb51229e44c7bf9bf6676e7n/aHeodo
2020-10-20BAL_SJ8875551589LW.docdoc bab707f338d98b9ae46b7775dfe552e80b39498b2703f95077f0ff3b2b622790Virustotal results 40.00%Heodo
2020-10-20FILE_PO_10202020EX.docdoc 2c098fc9ec5e14a94d73127218496cc9200f1d77c6799f35009b67bf45313451Virustotal results 41.94%Heodo
2020-10-20F3WZXYGX1.docdoc 621a14c4ff1196a5f40b5abd1aa47738a2855dcb1ac4f16c7e577d6f53935c08Virustotal results 39.62%Heodo
2020-10-2026461571.docdoc 61706a00aa6fab85343ed0d7b0505944440912b170374796f8a1df54ff125836n/aHeodo
2020-10-20EG4846779844HH.docdoc 92a7b39028f2bcf83296d5e09e65311b2f58f18fae952f1729e0f6cee6792754Virustotal results 39.62%Heodo
2020-10-20FILE_ME6119832251CO.docdoc 65e77a7fdaacfc77d7798aa1fb60ea3b8928c8b80889cbca1d664af5d26e2c5dn/aHeodo
2020-10-20DOC_5105354851948.docdoc b5933f1e9cda9927074ef0e3a34160c567aa03c76cdd96571e25349448e1a7c4Virustotal results 39.62%Heodo
2020-10-20PO_10202020EX.docdoc dc4424c660cc882687e934977d90d1e7725602d1d702466653d1968d2ac1a066Virustotal results 38.98%Heodo
2020-10-20I_HJH_100120_RWZ_102020.docdoc 4deb00a4faf8cd846d7255a2cd780aa8722c1a13e7a38efefeb981758a881d2dn/aHeodo
2020-10-20X_RD2047842480XT.docdoc 937cee303cc38262306e3f7b0d0203d2dce7610f5fbbcfe8d5799e1866704287Virustotal results 38.33%Heodo
2020-10-2092063633.docdoc 534d9419df41c2350d681ec677b6673e97f1177d08bd6650094fc6dfd010ad6fn/aHeodo