URLhaus Database

You are currently viewing the URLhaus database entry for http://prisma.fp.ub.ac.id/wp-content/US_us/xerox/Invoice_number/Fhbq-Zwqr_Um-FG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:120443
URL: http://prisma.fp.ub.ac.id/wp-content/US_us/xerox/Invoice_number/Fhbq-Zwqr_Um-FG/
URL Status:Offline
Host: prisma.fp.ub.ac.id
Date added:2019-02-08 19:57:46 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-02-08 19:58:02 UTC to abuse{at}idnic[dot]net)
Takedown time:16 hours, 17 minutes Good
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-09KIKN0479929855.docdoc 2fe889ee6e290f8dd9e7c4a72aa07998dff9605e19680b38dcc317f2ed7c70adn/aHeodo
2019-02-09ACC75285322382368288655.docdoc f13bdc15794eba12d18197a098689847d023530d33a54387f8f3894112e25f55n/aHeodo
2019-02-09US6248260721198935.docdoc 65bebf4b60bfcdca77338d02c016cc297fb0bd2c080a0aa3ff40179851033a6fVirustotal results 28.07%Heodo
2019-02-097749977526102012.docdoc af1789e75efb958c0d2d22736622f7e1d4f1c6e9645ae5ff1c2a59c3e9a57dc0Virustotal results 31.58%Heodo
2019-02-09US42389805327154095.docdoc 6f03b408d13644eb4d4f17eba0fb92c2905c5becc4fcba53b6bc8c9565c1af22n/aHeodo
2019-02-09ACC28403907626054071.docdoc 2cb235472f7a97d7cbe568447fa64642bf6416acf472ddc1311e6308a16517bdVirustotal results 31.58%Heodo
2019-02-09ACC02844874265041.docdoc 6f5e2f7c534be44b36c0df06a0bbcafbf72fa633e33998627ae6e6268dde555dn/aHeodo
2019-02-094707157732.docdoc 5ce42f9ec479887f89000027b43800f9e03c5e5c760193650b5e22279e6a686dVirustotal results 33.93%Heodo
2019-02-09PAY6255918875177.docdoc 352992986122ae1cc776ac7389078cce9222a0adc94ddb743e3ee75a4061bf71n/aHeodo
2019-02-09US3096778913160756.docdoc 05087b11e21dc5cb318f9b35b448ae12b1351073c6169554a075f09f382483e8Virustotal results 31.58%
2019-02-09ACC2999887357703307.docdoc e5ec0e796556497b8bea0d2597525960353082c43ed18845e53c20cdf1882f3bn/aHeodo
2019-02-09INSTR028719923684742.docdoc 826e4b469d1429ad9c749f13a72592df849100013833edc1b3ee7e262df0c0b2n/aHeodo
2019-02-09US567322473762420.docdoc 561acf43c7b8cce4f658d839455eab514366b01ae71b50a78ca8a4bc6ef40b41n/aHeodo
2019-02-09INSTR67033701960159.docdoc 3d576a11e841ec17ee0c551f770e9da07aabb8b22acdfa61310bfaf216b3b3c6n/aHeodo
2019-02-08M5425132980274.docdoc 12b7d14c5b2b2f9b418cc581e13ba1826ab44366a2655cf9ee2bcf244efcf47en/a
2019-02-08ACC6139865651027.docdoc 4aae6398e602432c0a2063c9e399ee6894043e0dc9825ecd8fdcd5476aa044c3n/aHeodo
2019-02-08ACC5824334034.docdoc 4dd107d93426f7e933b112bde796ee356aa33ffb5f18541b012490ecb9686091n/aHeodo
2019-02-08119309803434409.docdoc 3cccf50c378af6ef6675b1ac148b82c3ad750e71f3082cf3d907d88d59239f4dn/aHeodo
2019-02-08TP583769234.docdoc 48026c404114797c99095bb105e7f3d52a7215ca9596e49fbed6f8501d9b5c41Virustotal results 30.91%Heodo
2019-02-08ACC17194798797.docdoc 22ad45aaf536a845812fa0fc7ff45223fff0f635d38babe7611cfbd567b5322dn/aHeodo
2019-02-08US12871399674297575.docdoc fb7dec914775e26e015f802e8d7384128bbe8b4c844f94eba9d6c7c512b6c174Virustotal results 35.71%Heodo
2019-02-08US48535470045754827106.docdoc 052be97618d6e73019e00316750b3b846c2b5a667d135d8dadf5aaaefa966297n/aHeodo
2019-02-08PAY35481739386835416827.docdoc 379b58dc70893a9412209e4b1c525484d6732b8abc9b9f4d96c6bbe7b8b947een/aHeodo
2019-02-08INSTR58211437409.docdoc 97aa8d25a369a12c7512ed76e005fd055fa6898990ce3a6ed87982218182c62cn/aHeodo