URLhaus Database

You are currently viewing the URLhaus database entry for http://library.uib.ac.id/En/Invoice/985592504/QyKt-sC_NXzHM-eAJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:141129
URL: http://library.uib.ac.id/En/Invoice/985592504/QyKt-sC_NXzHM-eAJ/
URL Status:Offline
Host: library.uib.ac.id
Date added:2019-02-20 20:47:13 UTC
Last online:2019-02-21 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-02-20 20:48:02 UTC to abuse{at}vip[dot]net[dot]id)
Takedown time:8 hours, 0 minutes Good (down since 2019-02-21 04:48:30 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-21PAY467492364189220.docdoc 8c16f59af76fa8f09cdde9aeb65bfb6edc8791eac5154165e897e72ef04c9896Virustotal results 30.00% Heodo
2019-02-21US227023943647.docdoc 06c8637ad271aea1fa4cbd270ce643c8d630d3908df88398f06cad9b0813989dn/a Heodo
2019-02-21ACC2866456942656407.docdoc 7bca9566cc5217da968b100c78b615851dec6c9d5a62f52414d8cf4a55ada654Virustotal results 30.51% Heodo
2019-02-21US54239015918789.docdoc c4d2d9e19df870795daacabb84ca9d8e5f400c30c0d92a64c3bfbfd933f07c86Virustotal results 31.48% Heodo
2019-02-21EYMO2033885862.docdoc 541d9778452f1406109122db15161ef577331da8f89cb38174e61d6cc7118f5fVirustotal results 32.73% Heodo
2019-02-21PAY694997751265641.docdoc 8c18249cbdbe4d709965db788358e9ec053fc2f4309c53a11e11c85c6ab86722Virustotal results 30.91% Heodo
2019-02-21ACC31298959448.docdoc e88dd0545b70d9e2ab35edeb91b67fc9e8fd82e80716809697ac3d176b5ee018Virustotal results 30.00% Heodo
2019-02-21US403764430357.docdoc 8b94da4008ee7e958c9d6c5dba49ba6b9c7a7ddb61e85559e2ede128bb7f22d7Virustotal results 28.81% Heodo
2019-02-21WKPJD715996618055857.docdoc 0ffa66af30c25de60b1235bfc329ceab6ffd038fef0873d0c2137befed58ed13n/a Heodo
2019-02-21US204505811486.docdoc c60c0239798e85578c1a5a4bf91f5d03ce3e1d6e7df053be1a451756ee6110e8Virustotal results 27.12% Heodo
2019-02-21SAAWG6701710163929.docdoc dd8fc292e4a744bf2a649f653c8eb1443375de733234f72e0331c0843a155a82Virustotal results 29.09% Heodo
2019-02-20PAY40926824899.docdoc c35dc68437a3fc08776276f1ac12e51f07c35a43b2820f10eca7081bdb3d9ef7Virustotal results 29.09% Heodo
2019-02-20684320223454.docdoc 1e75c40c1a432f5751f395fafd6698443037f69432534a0ada185adb4b159580n/a Heodo
2019-02-2060322168344069220.zipdoc 62d371690a5ed65b7fe35c8193a82d5c406a3ab56eef4d1a3307aa4b180d9682Virustotal results 29.09% Heodo
2019-02-20PTBA36162490766215189.docdoc b5e63d30f7c7fb394bda84c9c34d77a54016f43d660e1a91e1adfb838cb34b8fVirustotal results 24.14% Heodo
2019-02-20S941733771.docdoc 5d12e0b6fd3401e70e111bb42f81da99ca1c4199acb159f02300d206f3892b83Virustotal results 22.22% Heodo
2019-02-2067560907725436727761.docdoc 8b1eb699d4fc07774672c38b6ce5668a249a7cd5801f8a99095b1a5c554ab752Virustotal results 27.59% Heodo