URLhaus Database

You are currently viewing the URLhaus database entry for http://ppid.barrukab.go.id/wp-content/INC/mvncfwehp8m-800875/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726451
URL: http://ppid.barrukab.go.id/wp-content/INC/mvncfwehp8m-800875/
URL Status:Offline
Host: ppid.barrukab.go.id
Date added:2020-10-21 01:15:06 UTC
Last online:2020-11-05 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 01:16:08 UTC to hostmaster{at}indosat[dot]com)
Takedown time:15 days, 16 hours, 2 minutes Bad (down since 2020-11-05 17:18:33 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22FW0024 invoicing.docdoc 7104dd32f9de62701f5d5a01ac763237757d11e8fa2c10ec24749f5791467fcbVirustotal results 38.98% Heodo
2020-10-22Invoice.docdoc c62002794ed88e1776376cf0144fdaa74155895bd71f5a69b781acf83818f56cVirustotal results 40.48% Heodo
2020-10-22INV_3396.docdoc 67c1b651e75a7c189396cf60ba8461c90336f917091b09d97b042a0ca7ef70a2Virustotal results 38.33% Heodo
2020-10-2101767329317.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo
2020-10-21501634633.docdoc 3498119a8fd01f12eb785bef90aa0db0abec22057cb338983fee714f612b6fecVirustotal results 32.20% Heodo
2020-10-21Invoice 00038440.docdoc d9c9cdb661798fec5696237b21371f7bd3b1fdac360a68aa3fc3d863e1d6173aVirustotal results 32.26% Heodo
2020-10-21GJ3 invoicing.docdoc 41355a097538a80c8204c61e7eb31f408568aa25e3593d587b0dc41e95838f6cn/a Heodo
2020-10-21PO# 10212020.docdoc 4d7508552733f0a42b7b2273bbd90b7e8135be0de22c160e89ceb830c00531eeVirustotal results 27.12% Heodo
2020-10-21HS0273 invoicing.docdoc 3c54fe2565b2e6ff66e9b1eb34fc93333f99d82c4c76d757292dd4e8c6af406aVirustotal results 32.08% Heodo
2020-10-21Copy invoice #9439.docdoc a5d750e425ab9de49e7b45ec31d09d8483feb56b88b7a91b68ebc88286e5fb48Virustotal results 33.96% Heodo
2020-10-21invoices 127 & 07248.docdoc cf82d0365de8c8bb9a11fe55d1c592563309c38f81dd2489d64320006b738393n/a Heodo
2020-10-21Inv_886902.docdoc 326dc3efbb3c157a00369c8ec16b1c404b95a85458b0417cccc92282178a4496Virustotal results 26.23%Heodo
2020-10-21MF3910448371MS.docdoc f04b54a77865e9bd2ae776e358fee27eb02b42b02ca3bbf7072b2bf1eabf3957n/a Heodo
2020-10-21October Invoice.docdoc 5ddd4814fd7f6793c23ae5d9593056b6b59b94a595441340a86375dfdb384b57Virustotal results 28.85% Heodo
2020-10-21Inv_2067.docdoc a5c730efa90e29c1794f91ceb2bb26d784adfc5cb4390d2421a94306174cf8d2Virustotal results 30.77%Heodo
2020-10-21Form - Oct 21, 2020.docdoc 2fab8ee623560cbdc4149b133dc5e91286af95e669d97e19523063c9537a27a6Virustotal results 25.81% Heodo
2020-10-21form.docdoc b1b68ff6e12d54572db4fa1a768108587786836e5e1c79f860f32d78e5f722e7Virustotal results 25.81%Heodo
2020-10-2103178008501.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21INV_7567.docdoc a9b5951976e5aebe82b1a18ef33e379ec5f3a36a04b89103649e54d7dc746aecVirustotal results 32.26%Heodo
2020-10-21form.docdoc df0901fe828ab8ff739461f32f011dd20e5cf34df476de9821c56d8bc6e9528dVirustotal results 45.16%Heodo
2020-10-21JM7 invoicing.docdoc 8d8971cd4eb8a2c26f5263e44299f9f468d43614dcccdcfae564420d264e0d29Virustotal results 41.07%Heodo
2020-10-215841593970FL.docdoc 29cdc20b4b547e832ab1e9c0eeff5b71201efe4262d8d542a8b359131f26ed1an/aHeodo
2020-10-21KNW-100120 SGMG-102120.docdoc 15680f3d4397a2ea2191e960421dd8650642415c14be15b1495f859bc6b9d7cfVirustotal results 41.94%Heodo