URLhaus Database

You are currently viewing the URLhaus database entry for http://ft.bem.unram.ac.id/wp-admin/13506582493/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287970
URL: http://ft.bem.unram.ac.id/wp-admin/13506582493/
URL Status:Offline
Host: ft.bem.unram.ac.id
Date added:2020-01-14 12:45:05 UTC
Last online:2020-01-20 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-14 12:46:04 UTC to azhari[dot]hasbi{at}unram[dot]ac[dot]id)
Takedown time:6 days, 2 hours, 11 minutes Bad (down since 2020-01-20 14:57:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-16SW_88844059.docdoc 5ad80a1e76e0b9721143378d01e5d05b04126b5d13d73dccfc69c0f4ede0b7f3Virustotal results 26.32% Heodo
2020-01-16F_55833516.docdoc 8a116004b69dc5979fc68fe9cf6a97d53ad4a41283415596f2cba5e136950711Virustotal results 27.42% Heodo
2020-01-16RP_PO_01162020EX.docdoc d099127211a3ea226604dcc6838d377ed93c6cdcd6ce5c444cb6d2759469a959Virustotal results 24.59% Heodo
2020-01-16PAY_PO_01162020EX.docdoc fe9f94df524752a01926d854ca7e6f4749725a2021a5e6dbd3ae0e7f04c886f2Virustotal results 24.19% Heodo
2020-01-16DOC_YR3V78Z2VTFZSE67.docdoc 1827154d65be4bbfbe6b4e3de7f9021f69dbdffea84e9d54109219811b01c902Virustotal results 22.58% Heodo
2020-01-16INV_POD_010120_DTS_011620.docdoc b56a6e25f16b75f974d90ac920bb38757ba86412909d0844c3195a7b0a04c757Virustotal results 43.55% 
2020-01-16SW_GZ9337624650QI.docdoc bc1ee7ea69d36c03a940c29cfce159c7e7225fbe58610eb697e091e0b242c08cVirustotal results 41.94% Heodo
2020-01-16FILE_BNWZ1JD8GMSP3JXU.docdoc 6755b22aabcd9dae95e3e99cacfe217231c85f91ed30953a1afbeab582aba025Virustotal results 40.98% Heodo
2020-01-16FILE_RYD_010120_OTK_011620.docdoc 66125c09e3acc0746045c7810c06d335037120b024e5ad802742f533fad7a008Virustotal results 40.74% Heodo
2020-01-15REP_SZ2367962545SO.docdoc 4f2436c9a27f11930281347fb74e605bb0deeaec69915df083fc9345cca5027aVirustotal results 40.32% Heodo
2020-01-15FILE_395321864725.docdoc c1c7fc8ee76da4f1696fa2d918472cacd777e5fe281acbaec5d12a85d98fcab5Virustotal results 33.87% Heodo
2020-01-15UEC_010120_GTW_011520.docdoc 5cef7f012587358911420986b0a10b3afc376e71cbcb62ae2369409a2949e714Virustotal results 34.43% Heodo
2020-01-15SW_91566766.docdoc 325df5875941d1bf51f7c6099269c3396771f3188c57b74bd17c51373b32b1c8Virustotal results 32.26% Heodo
2020-01-15BAL_PO_01152020EX.docdoc 3bd995e4229e3d5adb81c3572c5278e730524b0774cc7a8c4ea710bc4be1ae33Virustotal results 32.20% Heodo
2020-01-15FILE_875362620134274692074539.docdoc 4e81d0dc2cdf2cabde46136486114a319b033aa0e1e0ef7eba7dcb7117ca2214Virustotal results 18.33% 
2020-01-15J_84610852478.docdoc 51f267fcc86d1c12e28ff777861f305389aa23ab29ac4aa0980309f727d6fc46Virustotal results 17.74% Heodo
2020-01-15FR1226645719ON.docdoc e4fa19c4736ffb554aacdb6de08c4ad081fd55105dddc85b31eac5c6082e601bVirustotal results 18.33% 
2020-01-15BAL_QSP_010120_GQJ_011520.docdoc d3edd09e8e4e9e89dbff176e69131f189175abf1a598c18593a3bb194fc45c2eVirustotal results 37.10% Heodo
2020-01-15ST_MG8GFVH27.docdoc af2aaa948c745e2b7ebf805f0198a4207481e101744fd3667df898de50c5792eVirustotal results 32.79% Heodo
2020-01-15RP_926434849694895233.docdoc 556f0f62580588094bb0d595bdbb880b58a48148af61569258c9a84653374cbbVirustotal results 30.65% Heodo
2020-01-145118089487878117453413463.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23% Heodo
2020-01-14BAL_GI5171946094QH.docdoc e8e877eb89bc1a478fee7e89597bcac889a3776e27aae4692b63920428f58e53Virustotal results 19.67% Heodo
2020-01-14ST_OS06ZMWASE5.docdoc 7f831b1e70be159d8194b2022de5a66d9784ac6959ddba38be95dbf6b30ea93fVirustotal results 19.67% Heodo
2020-01-14REP_W2EZINB5QDB.docdoc e3cd5ab045097c55bcb00a1cdc84e11c8d7214e15f536baffd899dfb8e0a3149Virustotal results 17.74% Heodo
2020-01-1411873253427.docdoc 66803a33f7fcf06dd846a89712009fbf7c3d24c16d102e0fe9bdb2fe04538f5cVirustotal results 18.03% Heodo
2020-01-14SW_PO_01142020EX.docdoc 9ee85b399435a194b9b67f49143134a823ef4dc87f95970c3516773b340fe9afVirustotal results 18.33% Heodo
2020-01-14FILE_PO_01142020EX.docdoc f5f4d5f08a7cb7e623d0bbfae4b90f9cf9151135d1218fc30b351b23903cbea3Virustotal results 17.74% Heodo
2020-01-14SW_55508376.docdoc 2034078fa59ba80aa4ea104fadd6e28f7fdb58220f8a6c434014ec88a007b0ffVirustotal results 18.03% Heodo
2020-01-14BAL_PO_01142020EX.docdoc 4e1c36be80c8d49de9d619166b44e070c37538978fd2b281547e1ceb47c90afeVirustotal results 16.13% Heodo
2020-01-14INV_PC7579588266ZA.docdoc f55d03e3ad7e00c22487c4297a898c96e36b144a5619d181623997b6b4782d13Virustotal results 19.35% Heodo