URLhaus Database

You are currently viewing the URLhaus database entry for https://www.gunungkidulstone.com/wp-content/DOC/3DL4vWkrZ8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729598
URL: https://www.gunungkidulstone.com/wp-content/DOC/3DL4vWkrZ8/
URL Status:Offline
Host: www.gunungkidulstone.com
Date added:2020-10-21 14:10:06 UTC
Last online:2020-10-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 14:10:11 UTC to abuse{at}digitalocean[dot]com)
Takedown time:3 hours, 28 minutes Good (down since 2020-10-21 17:38:56 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21arc 20201021 MM8017.docdoc daa1056189a708c56aecf3c760fe3c15eda062b969b53cb871f1e44a934be86dn/aHeodo
2020-10-21File-ZR5898.docdoc 1c9f16cb8efe6d27052e6e20471366e7516176926ff0f7c04038156016be4b0dn/aHeodo
2020-10-21Attachments_2020_10_21_7538.docdoc d73ed4bc0c34c0cf8f5ba7b2a1baf0983d039f22dd04a5a27645ee5a0010cd2dn/aHeodo
2020-10-21LIST_WWZ6575.docdoc 23f330f0bf1a63c1c16750cb36dac328a7a4fe0b283187001340c613d73b8c38n/aHeodo
2020-10-21Mes-2020_10_21-7266025.docdoc 2d2ac5cd6f74a5856e83c7e4c12acc89c52216c00e83f8d84d58aee357824881Virustotal results 27.42%Heodo
2020-10-210735-63312.docdoc b0a31c904ff4253b07ed800ad34632f96db4ffb69c86f8df2e22ffbccb9f3705n/aHeodo