URLhaus Database

You are currently viewing the URLhaus database entry for http://meunasahmesjid.desa.id/NB0K5EE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:94478
URL: http://meunasahmesjid.desa.id/NB0K5EE/
URL Status:Offline
Host: meunasahmesjid.desa.id
Date added:2018-12-13 20:05:34 UTC
Last online:2019-01-15 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-13 20:06:02 UTC to abuse{at}jagoanhosting[dot]com)
Takedown time:1 month, 2 days, 23 hours, 19 minutes Bad (down since 2019-01-15 19:25:22 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-16this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2018-12-14BVS6DGWZ.exeexe d171acea3af3a65054dbc1478a4a7b444178810852c17a8f0c5f74d05458b15bVirustotal results 22.86% Heodo
2018-12-14Xmzh3uJOL.exeexe fbff66ff8226c949f42d9ef268fee27278df5a236a0341381afbbc57e1759505Virustotal results 25.71% Heodo
2018-12-1493RxnQqx.exeexe d4c8be90c29432d1551a6623274919ba2f40e4426803ff4cda2886543daf8ad8Virustotal results 22.06% Heodo
2018-12-14jj0fRsDpy2.exeexe 92279e9bde3bd909f1d9d743ad4398ca1008ae7ee5e7f462e6018935b229c4e3Virustotal results 22.06% Heodo
2018-12-14pTIMQYmIbs.exeexe 8a3f5372c58bdb0bd3a74addd16c9f4d8d881446e302420797cdf3b6622498c3Virustotal results 23.19% Heodo
2018-12-14ma46SOXYx.exeexe 570b5a845fb2729dcd097b2062fb6f72cc7f968748521572089916df0918ec11n/a Heodo
2018-12-14hzeOXZODx.exeexe ff6791ba46d519603a48f8941ea8d4cd6fbfa304598c339c00af0882142fa060Virustotal results 25.71% Heodo
2018-12-14IX6mUYOEvGc.exeexe f0f628fd84e94101658a4bd291b8918cc77936a6dbc2dcdca9a019e30fcfa26aVirustotal results 20.29% Heodo
2018-12-14C9gWL3Xd3.exeexe a8a88e0ea34cf5f792a3153a0ca4fdc078404564f6f521b172c1d4135644150dn/a Heodo
2018-12-14UFYKXhbwxb.exeexe 44964fe37d504c13d35f125ece13ea56e89278b88210875514335b63f8d5ccbcVirustotal results 25.71% Heodo
2018-12-141a9KWNn362.exeexe ba75e02defc68a900fbac1ff78b8709eb0ec14d06db5163ab67f66eb1861bd40n/a Heodo
2018-12-14jMoMora8pJLb.exeexe 82c2696c2f12e1554b3878ef88dacc1ddb7f8fb2a9a2bd67d1d4c07b0b8af25aVirustotal results 27.14% Heodo
2018-12-14HK977kT84G.exeexe 4c32d8604443fa8cc0d9c427953d3f3deef132cf1e098de3287d6a5e0c7bec66Virustotal results 28.57% Heodo
2018-12-14qOGZ7V6q.exeexe 405e6bfec8fa4f8b8983e17a7823d4e0347d5b676946b5510874768ef3c24c7eVirustotal results 29.58% Heodo
2018-12-14ejAQb1gx.exeexe 247657d6bafee5c3fef8e3f19c35f77d43635a4fde4ef84187353dcddeeeb67eVirustotal results 25.71% Heodo
2018-12-144D8l8Gaee.exeexe 6f598635d2d8b3677543aa75071bc8d79948675f04b161fac96eda8493b522fcn/a Heodo
2018-12-14Y7g36juLHF6.exeexe 6ca8bb0de1d669b2c2eb86af84479e24db962599b23bff5e0b816515d82c7084Virustotal results 32.86% Heodo
2018-12-14nVRUULBKPI6.exeexe d3292cffc1aca8e008435156855d40e6bae1a0c40e7c70929b1f3bf917bab93fVirustotal results 31.43% Heodo
2018-12-148bllDD3L.exeexe aeef53c0c035dc1f20ab76c3d5b431c791e872b09d832fc913d5b4ba2986ff76Virustotal results 27.14% Heodo
2018-12-13RSydFcGAOKl7.exeexe 392b1e9b1d943bf15c0668b0494fdb1a23eb57f44e0afae26ebcf9ed356528e4n/a Heodo
2018-12-13MpPq9593.exeexe b5575c456dcdf0ad5aa911f72efafa176063612b4ede00a47f58ea16b0eb79a5n/a Heodo
2018-12-13JqqsgEEZ.exeexe 764347a55242c76fe4d6a92cb04dbc2e5fbc13db94d6843335f8a66ff1905bf9Virustotal results 18.31% Heodo