URLhaus Database

You are currently viewing the URLhaus database entry for http://fisika.mipa.uns.ac.id/icopia/files/kidrh-wzdd4v-ziwxi.view/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:154950
URL: http://fisika.mipa.uns.ac.id/icopia/files/kidrh-wzdd4v-ziwxi.view/
URL Status:Offline
Host: fisika.mipa.uns.ac.id
Date added:2019-03-08 14:42:04 UTC
Last online:2019-03-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-08 14:44:02 UTC to abuse{at}uns[dot]ac[dot]id)
Takedown time:7 days, 22 hours, 49 minutes Bad (down since 2019-03-16 13:33:27 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-10US382504767948.docdoc 34c5672ce5999e36e86b57f993d548afad5323c9848034d4bce93a5c2251c1d4Virustotal results 33.96% Heodo
2019-03-10INSTR96854104746133.docdoc d7da73c3986996a30d169820819bfa8dd69a7bee7c787f465b55fa8beae39f99n/a Heodo
2019-03-10ACC04214108472670.docdoc 5c79ca3b6537fce9529645f3226063780b790888e57bd7b3c9f66caf5f9fd652n/a Heodo
2019-03-104561491851.docdoc b8bb49b90fb27e884b306926587e6a338361d4c2c5ed28ff98f3c0cb589f5a1en/a Heodo
2019-03-09EZ44186192618723807.docdoc f230c108c5b7a911954bdec4ad017d51102a7cd0be2c97dea121c25c771cfa8dn/a Heodo
2019-03-09US85284060630424229080.docdoc 91e48234c6d92e6ac6476b22218ee81c27a3b5bc29869a60f652f7c283f17d7cn/a Heodo
2019-03-09INSTR9272831933.docdoc 155099328610d7a4dc8154ca04b4a5b468f238fcdf45c92e109ff0614ad4d990n/a Heodo
2019-03-09US099521448872576600.docdoc 1a2a77a406f95263efbe157d16aad1cb2fcda6ccc08a4f295d67c782a3a96956n/a Heodo
2019-03-09ACC93263136709315396.docdoc 5f52c07dd3445dedb8e5a33125573141391c732f59de0649ade9b55466f6d125n/a Heodo
2019-03-09103022783.docdoc 5f43d94fdf37b2a7a9f62507526f7b20337ba2ca85b3381d8ccdfb74e7557ee2n/a Heodo
2019-03-09928090555059175.docdoc b32e52605499e96266866e6f61d42994ef915191dd756537f4a307d2d91a303an/a Heodo
2019-03-09US73191548799448.docdoc 824d10ff8cca537feb8fe42bbedc3a1d7e1d4f87f054e8c184f266e6f46f5ed6n/a Heodo
2019-03-09PAY274404722655594.docdoc b5463dce7673b2dae3cdb6bbec7e9f2fdffc495098586fecb8a4a523ee6c6938n/a Heodo
2019-03-09INSTR20803304687289356203.docdoc 6f5616d7df481fd073f34821b8e28ba6c34a4dd9b372d5dc09f470f450811201n/a Heodo
2019-03-095062525417301030.docdoc 3a24a7c890d42e6abec4fc67564e44583ea1646d67d7193ce12c9f97fd609140n/a Heodo
2019-03-09PAY66013678595.docdoc 2a10a17eb043413bac94143cda9e67c4ad7ead28e2f7ae960601885a7430dc35Virustotal results 35.19% Heodo
2019-03-09PAY65995961934.docdoc 8e61678378e40e0e8dca86021154b0e286405c16c7943e24238abad63f2cdfcbn/a Heodo
2019-03-09INSTR90481162247.docdoc b81cda0569ded7dc459797baf1fad0e4450489f14316fc1c4f4484a8f00ef86bn/a Heodo
2019-03-09N84886301255.docdoc 6e46b17e22f93ad24a43e99ea649c0a3b4a3db0f6d9285b7b4e86f73e7afca55Virustotal results 37.50% Heodo
2019-03-08PAY927621161323352.docdocx da1b47eb285b4a7c79c91c9f33b6a4088b8b03c175bc900669211b9949fd8b35Virustotal results 19.35% 
2019-03-08766186366222010.docdoc 6a0822d81f458e3086f53fa70904cdfb68c89c48c17470bd211765a2cd886149Virustotal results 28.30% Heodo
2019-03-08PAY743193758067580781.docdoc 0a9c905a4e041543a9e0e3650b6881444495120aa72732785d74990f3518f0ccVirustotal results 27.78% Heodo
2019-03-08VWA08176892734943326.docdoc 3800b8a255df8265c7912c2b8bdb09cfc191bd0b3e8cd9debc9c20d6c1b57070Virustotal results 26.79% Heodo
2019-03-08PAY8820951132169647.docdoc c212c359996c552bd2c5f90f928aabe2df145897bb86059ffa2845fddb4b7c01Virustotal results 25.93% Heodo
2019-03-08PAY55515620154035.docdoc 1369a693f5cdc944f89a187b8030095b77dd07c93dcf6489a2519a41391cb2dbVirustotal results 24.56% Heodo
2019-03-0808081876458082.docdoc dc6d15cd945e8cd7e8ac2c48f92f283c24c332efe41304964ecde111a31bada1Virustotal results 25.45% Heodo
2019-03-08DLKD9694190409.docdoc 5c910f3e1b2c2767074476c4ccf62c3e62bd8e78c49b666583c16cb1ee42c0c7Virustotal results 25.93% Heodo
2019-03-08INSTR886624020359.docdoc a4fac8f814e04e5723081d4b35d818858a46fe1ca2e9620b415947fe73ed2d14Virustotal results 24.56% Heodo
2019-03-08US85563679990681892.docdoc 4a13f66450484e652dff2c79c192ebb5ec2e8b1988edb8898fcc3a872bb284d0Virustotal results 22.22% Heodo
2019-03-08MN1193081370596.docdoc 2f92ef85141c58056433f18636f6fc20bd374c447dd2f50486aea48881dbd612n/a Heodo
2019-03-08UEGO99627320230733584025.docdoc e998068f7e10a188db7074668c6578296e9e6f39aac5cd482b0c153bb8cb4527Virustotal results 24.07% Heodo