URLhaus Database

You are currently viewing the URLhaus database entry for http://himatika.mipa.uns.ac.id/wp-content/O4_Hx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:182390
URL: http://himatika.mipa.uns.ac.id/wp-content/O4_Hx/
URL Status:Offline
Host: himatika.mipa.uns.ac.id
Date added:2019-04-22 23:37:17 UTC
Last online:2019-04-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-22 23:38:07 UTC to abuse{at}uns[dot]ac[dot]id)
Takedown time:6 days, 8 hours, 33 minutes Bad (down since 2019-04-29 08:11:44 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-24U_i.exeexe 95d709d21907afca6c95b2e6599ebecc75cac82916b9a82ce89d811b948e3180Virustotal results 22.73% Heodo
2019-04-24R_8.exeexe 085e6a56fdb7daef2203942cab25721e40c92fc74846a1ba1278afc2c1601a4bVirustotal results 26.09% Heodo
2019-04-24y7_eV.exeexe 3de3f82ba6763b3d6b09dea9b7b1badc7d6fb8af4a90eea4689055911f3267ddVirustotal results 64.71% Heodo
2019-04-24t_Yps.exeexe a9f333b29971aff0de5b070be765e3e81135f6477f02afba879bd2638183d563Virustotal results 23.44% Heodo
2019-04-24N4Q_UD.exeexe 6d54d5e52aecdd7abca8d6c5ac9fda1464595b96df9bd6b629604bc289cf6ffeVirustotal results 23.88% Heodo
2019-04-23C_ihv.exeexe b73d0d387e795267c39d299027c57ab4e610b0e02d79c3b6aac0273e601eedc2Virustotal results 23.88% Heodo
2019-04-23d_hPk.exeexe b2bcb7fe83ffb8606ba25c652c5dfa2b2cf0dc694af39285546d44910b39f208Virustotal results 25.76% Heodo
2019-04-2355_2.exeexe f6ed3a56a0cdf245c8e5c9458bbf13aca9ac83c5659f0b315ac8c95a181db172n/a Heodo
2019-04-23l6_JG.exeexe cf7881f855a691cd37fb706e4fa63866d58b63ab4542df402aa0dd005bfcf436n/a Heodo
2019-04-23R1O_GTe.exeexe 053b2dc44fcfac0e20f9b8c630f31a697877fc7b797cebedb0ce4cb17d504906n/a Heodo
2019-04-23SZ_JK.exeexe c7c21c207c985ea39949200116809dfc83a71026574283935a98ce4fe945853eVirustotal results 45.07% Heodo
2019-04-233VR_qgl.exeexe bcb87d9fda073b879526b88de2264efa2bb714e34d1e94eb68c9be6d73c829a2n/a Heodo
2019-04-23v_M.exeexe ad000ebcd310eb54206101bd7ab1c1bd0d182096855f69068cfa8646957ef088Virustotal results 42.86% Heodo
2019-04-23U3p_4.exeexe 8ae1b2d3af3722a78c9ec50941b9580caaf7c6cbefeeb6f8f4f6dc75e4bb8fdfVirustotal results 41.18% Heodo
2019-04-237x_Ps.exeexe c16924cc3dc51d0ab690c49cbb083f495e932e2cd42a8c3eb385d4789acc7d29Virustotal results 38.81% Heodo
2019-04-23fkO_k.exeexe 2278ccbadd8c85862c9dc38ada4ccaa1fd179cb64cbf87685f35f962c3d5d2a3Virustotal results 34.85% Heodo
2019-04-23kOF_nYF.exeexe b903fe25f91ba94f05cd8cdcdecee0be90832071740bf39489a2c0a887779013Virustotal results 35.38% Heodo
2019-04-23jPs_vmk.exeexe 5b6186fa6a707140877e35bd85fa471fed39cb89095be7c2c3cd053713d79734n/a Heodo
2019-04-23tt4_l.exeexe aee218db0f1932c2e6e1a961d46fb1aa4b2a55265809a0be9b13d6b214a80e67n/a Heodo
2019-04-23tR_4S.exeexe 9a53ced33decf87ab51e53ffe3b1f216917d9ffcce5acae2534e9f743e8984b4Virustotal results 30.30% Heodo
2019-04-22C_n.exeexe 795e8d479f6d3c8de3899f9bc45b4232201ca11dfc87e8c90024eaf59c718e4en/a Heodo