URLhaus Database

You are currently viewing the URLhaus database entry for http://ics.co.id/cgi-bin/invoice/2sxopjo5buz/1leypkb4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:727058
URL: http://ics.co.id/cgi-bin/invoice/2sxopjo5buz/1leypkb4/
URL Status:Offline
Host: ics.co.id
Date added:2020-10-21 05:55:41 UTC
Last online:2020-10-24 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 06:01:06 UTC to abuse{at}pc24[dot]net[dot]id)
Takedown time:2 days, 19 hours, 39 minutes Poor (down since 2020-10-24 01:40:23 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21WUG710B2XVA7O5.docdoc 7606c587c9a22687f99deb394aedd9be63d066c53c44d9cb78dc3a03319f670cVirustotal results 29.51%Heodo
2020-10-21FILE_YGC_100120_MLO_102120.docdoc 8a2b904ad14790b5a69146c0f573dc2da8adc472159bba2aed0afdfe0a550d5fn/aHeodo
2020-10-21ZIKD_XQF_100120_DGQ_102120.docdoc 02a8230dfddee28c717cc288e1573b5a44194cebefd65b8a20d0e37e2e086a1an/aHeodo
2020-10-2150994922.docdoc 25c71c161f7a916496cd76d407fc6a0863e2f36fa50e8b2cb886b5ca7b853dfan/aHeodo
2020-10-21A_PO_10212020EX.docdoc d2a68a5159ea637fa9428d39a0d9469c6c2db0b16b2de2593070c17a0ad49520n/aHeodo
2020-10-2176009808.docdoc a2767289b35cab514b56d67ba9c1c02f16035f42f8a1f65307e71cf9d9175206Virustotal results 22.03%Heodo
2020-10-21U_PO_10212020EX.docdoc ffe949d9c7b48175007f45137edbfd9aae251ee4e1977a547bbf506434dc8729Virustotal results 33.33%Heodo
2020-10-21REP_71886774.docdoc 726fe6b07eb73d6068f54ed6a6d61d76252af6ae080d1e41194e36dba8106a4fn/aHeodo
2020-10-21BAL_AAV_100120_JMT_102120.docdoc 2613c4d78a8daef9a9fc119072017d73ea4651234942d2d2c57683baae0e86d3n/aHeodo
2020-10-21BAL_XMF7K2V.docdoc fc956fdcb712699a094490c10177653c5df72d2913d775aeb75d9c676f04e31bn/aHeodo
2020-10-21938680907507460.docdoc b77d2293e1769638ff23750ab476d2eae143a5bbf834e756d17505298ffc2776Virustotal results 29.03%Heodo
2020-10-21FILE_LQT_100120_OZT_102120.docdoc 1ade5184899b623fc4bf9b7caacde819e06dcc9234a962622c056349092327c1Virustotal results 27.42%Heodo
2020-10-21S7JBOFODCL91XCK9.docdoc d2116981397601f48095f1a584c948e2e623ab4f0c5b2f393479cb20d67bfa90Virustotal results 33.96%Heodo
2020-10-212040001945107820923.docdoc 1e61f3c2c68fda87e0f2ba6a98d5e8ef53a5aab53b29c60be7ec3260412dbd0dVirustotal results 33.96%Heodo
2020-10-21FILE_AKD_100120_QDX_102120.docdoc 752491c57c15c686f143528a86da3db2cd1c4bc0513a2dcbef8d2ee47520f84en/aHeodo
2020-10-21FILE_36369341.docdoc e88388bec3164944678627db062b753e76b6f7f710a9fabc43dfe69e7df2f366n/aHeodo
2020-10-21INV_2446958092368092432470.docdoc 71e55ad14abd213d5627b65f8f045b2c9337c629a556868c692376c331d9fa58n/aHeodo
2020-10-21BAL_PO_10212020EX.docdoc 442199396365c09418756cb80ff20ce46129c4a0cc2cfc6dabf5e8bb2cc42437n/aHeodo
2020-10-21ELX_100120_MIF_102120.docdoc af36ad567085faaef5425d233641e227fdf842e426001e855103b942dde705efVirustotal results 46.55%Heodo
2020-10-2133297781109842.docdoc 71c25e3712abdd3d405b0a43f2819fb51d16dd9bf3c5fd5c9ecd04b028240533Virustotal results 47.54%Heodo
2020-10-21DKNX_18917107.docdoc 453c4b4cf3a5fda7d48005d020112c06ebcbcf478ead4ebcfacf25576781bb2an/aHeodo
2020-10-21825JX3N9HT3.docdoc 70a369ce3943f743ffc7740c3c003a5f00705abf0505641d7d193d5cf79b8dc5Virustotal results 50.00%Heodo
2020-10-21FILE_JZ9847220520NH.docdoc f6ca28aa0ec1ee28ce246d787de062e5b78554ec2cfc62fbf00db085c177b074Virustotal results 40.74%Heodo
2020-10-21SX_4666884797404985391.docdoc 39a7385578321db9d477ff19e7087b03d3c57076ceca16fc2af049c087f72343Virustotal results 38.98%Heodo
2020-10-2170777109.docdoc fdf5102af9db589345a5c7d4e747c98489a7341147058b2a42e337a03fa62baan/aHeodo