URLhaus Database

You are currently viewing the URLhaus database entry for http://ft.bem.unram.ac.id/wp-admin/Reporting/8hzv84kh09/1i3r-909425343-22-c8003n-d5373fllvd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273439
URL: http://ft.bem.unram.ac.id/wp-admin/Reporting/8hzv84kh09/1i3r-909425343-22-c8003n-d5373fllvd/
URL Status:Offline
Host: ft.bem.unram.ac.id
Date added:2019-12-20 00:28:06 UTC
Last online:2019-12-23 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-20 00:30:03 UTC to azhari[dot]hasbi{at}unram[dot]ac[dot]id)
Takedown time:3 days, 17 hours, 27 minutes Bad (down since 2019-12-23 17:57:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21RP_LF9054901441YA.docdoc ad253e6647362deb3c0d03399e7f512ef78a155763d032eab642d24c4bcec1b8Virustotal results 50.82% Heodo
2019-12-21O_50203800.docdoc 0dfb5cda8b86af6c45b6bd4bc68f9e23f7b6723b29f905008f1da435bfb93bdaVirustotal results 49.18% Heodo
2019-12-21PAY_GWHTKXDQSXYNAQ96.docdoc a44031feb2a71980a0980377c8f7b6f3b5b9dfa0f708556dd420be323c7e1a38Virustotal results 46.77% Heodo
2019-12-21PAY_203199873642026800808480.docdoc 08bab149c893a44f23ec39c10a85432c1180d99c868dfee6e7603a215f1c37e5Virustotal results 44.26% Heodo
2019-12-20M_JED_120119_VMW_122119.docdoc e23bc5ee382cc5f5a5c5a62deca1d119ee4347bfd72aa40765a336f933d1f7f8Virustotal results 37.10% Heodo
2019-12-20DOC_558904477304349647134.docdoc 085190935b08f49102610d5161e97892089f567965412b270f354cf088338edaVirustotal results 32.26% 
2019-12-20PO_12202019EX.docdoc 79e3cdd3341c2a20f5f88852caecd48fd292124c4b9e649a4c29305142ceb114Virustotal results 28.57% Heodo
2019-12-20BAL_QY4605530763CZ.docdoc ee4501eacafb83e4e74b484d060a2f02403635a851e87c2ee47d055dc01d8611Virustotal results 28.81% Heodo
2019-12-20UYS_120119_FFZ_122019.docdoc a95e5f3c88c9004ba2daf3ee43e7ade9b2245c535c4cb19cdcad348f261f2874Virustotal results 29.03% Heodo
2019-12-20C_JXD_120119_EQK_122019.docdoc 050f8bc2582036b0cf0d47a35c265fe0240f670f863d8a5478eac83f7cce1179Virustotal results 29.03% Heodo
2019-12-20PE7355434086ZL.docdoc c19e4f9564e304e11d679ca37dc75ab35b3feb1f6e63df36add9dc12cc43e6baVirustotal results 27.87% Heodo
2019-12-20SW_VFT_120119_WXF_122019.docdoc 6fcafbb8d2f4e90853451e5aa49f2f79b3be844072b59cca9e9370035b832c90Virustotal results 27.87% Heodo
2019-12-20INV_HH9879189773PT.docdoc b1030547b0925eda5c12565647d50e0803c6dfa7e5690961187a4f41e0cdf2f8Virustotal results 24.59% Heodo
2019-12-20MWWIDXCL35V6NH94.docdoc 5f1b3638392487a23f76624addfdd5e8a540db84fc527ddbfe758c44330f5867Virustotal results 24.59% 
2019-12-20QC8UKZ3K.docdoc de1925967758e4dd7954576cb5dd56508bdbe278cc8b737e33b046e73253096cVirustotal results 26.67% Heodo
2019-12-20SYTU_17882206.docdoc 19f2c7093452e7e5230593bed7cbcf8ce570ee2eadd6fa0513349c4f2dd4a175n/a 
2019-12-20BAL_13553169.docdoc b3ae698b4cec93800dc56b22d8f19cfe3e8c625e148ccf96e81b7c742b8c8991n/a 
2019-12-20SW_ZHF6HP9.docdoc 07c8176b3a48a0959727b1547ade4e09f4ccf0217be152cabc77715f119841dbn/a 
2019-12-20SW_AP12GELENE4MGKGT.docdoc d0c6b8f75ee6c9b4ea48634988b5e0bf4b315c503a6a2304640bf3138f7c89a6n/a Heodo
2019-12-20FILE_WHA_120119_SYJ_122019.docdoc df5a61979c588234e81bff857f2d437d05f484de63a4ba77b2f425709fbe4fbeVirustotal results 31.15% Heodo
2019-12-204812160881.docdoc 88dea847c0d9ad574162859c94ca13185358866f1ce7682c2c93a3c2c5e6ffc5Virustotal results 31.67% Heodo