URLhaus Database

You are currently viewing the URLhaus database entry for http://ft.bem.unram.ac.id/wp-admin/YfYVXdrS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290238
URL: http://ft.bem.unram.ac.id/wp-admin/YfYVXdrS/
URL Status:Offline
Host: ft.bem.unram.ac.id
Date added:2020-01-16 18:31:03 UTC
Last online:2020-01-20 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-16 18:32:02 UTC to azhari[dot]hasbi{at}unram[dot]ac[dot]id)
Takedown time:3 days, 20 hours, 24 minutes Bad (down since 2020-01-20 14:57:00 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18invoice-NAOX8169_891223.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18Inv YSJ414_172178.docdoc f3cbdc44faf63684f682e6faf078854ba2d08c4f80284ccb192508021087101fVirustotal results 24.59% Heodo
2020-01-18Inv_GBVA7_35643470.docdoc c18f5e41c03d90485d087d382d3953e3ae125d732a5c8bb1684de08cd58d79bdVirustotal results 22.95% Heodo
2020-01-17invoice-IK0_079024.docdoc 72657fb7f9c82eef21cf35110c863a46d60dfb81434c9b08cdd0c297a2b45710Virustotal results 22.58% Heodo
2020-01-17Invoice-G9667_136341.docdoc a8c4e3f1c16e9ff3857699615d8f6bd392a4d88dfdc6f9dd9b43b523ac3158ebVirustotal results 19.35% Heodo
2020-01-17Invoice_TRW4318_96782247.docdoc cf8f7f9ebc40351bf67d9c14743199a531bb1c4ab1155316debc244c85a29cacn/a Heodo
2020-01-17INVOICE-FVF1120_326757544.docdoc c1773292833e3d31b42687618328bfc2e893bc2262b9d3ddeda0dd585eb5446aVirustotal results 19.67% Heodo
2020-01-17INVOICE IN19_64327583.docdoc ba41ad73fcdce6b4e813741379ada938bdc3b9f751255d0f38bf9e39833dd000Virustotal results 23.33% 
2020-01-17INVOICE AY7492_000875.docdoc 8135652b106f2b85795db8ea0696bc8b19b68a1fc008345df6b797e19b88084dVirustotal results 20.97% Heodo
2020-01-17Invoice_RK41_300621961.docdoc 127fbb144e09a37a3fb74478730d2c431fc0876897035497e7dce1c49d3d539fVirustotal results 20.00% 
2020-01-17Invoice-4_1199845.docdoc 298a10ce8a9fe8dcc5947d02585a549d1c9d0609c7d11473ff4c8dfbb3a9f801Virustotal results 21.31% 
2020-01-17Inv 3_78534241.docdoc d049f5dfbbae48f87b5161aa9f6cc0fb667205ddcf65439de559dc8d136c06a1Virustotal results 19.35% Heodo
2020-01-17Inv-JRU8271_435696399.docdoc 191b8b7a7b8d1217997804b5f985819c099021f8a0fee93e1e9201004ac8667aVirustotal results 19.67% Heodo
2020-01-17Invoice-VC112_97907248.docdoc e09d6c6471feb40345f420439b9c6a3a12ad485be6d8be5a8568b50fcee2b422Virustotal results 18.03% Heodo
2020-01-17Invoice_NA7462_63339949.docdoc c682de9b99812ab7c470a026d17e1060364b9bf4e1890d733b05ef312452f8d8Virustotal results 19.67% Heodo
2020-01-17invoice U68_603953.docdoc f5afbf6f6037177757cc1129985541003a253d7798a2120e9c1e823d252f31a5Virustotal results 18.03% Heodo
2020-01-17Inv 8049_95196116.docdoc 705c0fe4297531835d50b0458ac82dd33ecc2372332fa70d25d6f723ee898671Virustotal results 19.35% Heodo
2020-01-17Invoice-TOK4_37272242.docdoc e54979318c06a7cc3d8fb5f00d32d0fa2a169f8447a224ec8822749071c550f6Virustotal results 37.10% Heodo
2020-01-17invoice-S6308_959275201.docdoc ca551d59d80fab6780d94efdafd2dd9de6e94e135ab5debe1ef30d520df563f7Virustotal results 37.10% Heodo
2020-01-16INVOICE AT2690_876957.docdoc 8cf5201a2f5adc4ddd6ec8d61ae4674d9c4df7554ef49f76052275f95db6a3a6Virustotal results 36.84% Heodo
2020-01-16Invoice-PH046_95081830.docdoc 9f96a0185b66b8237cda06c1df6528fcf10b9f1bcf2f99eaaf74c4fe71c9ed6bVirustotal results 36.36% Heodo
2020-01-16Inv-OKQ8943_164909883.docdoc 6181d694653add4a58a2dc8535371c420cf35014cb78f8ed1447986900fd103bVirustotal results 35.48% Heodo
2020-01-16Inv K193_502595.docdoc d138359ab7543bbfedd4895fb0e815b5a41453c87e601a5a4ab2d04363a3aec0Virustotal results 31.15% 
2020-01-16Inv_NZ85_471109.docdoc 50335cd24e5daff24940f21f21107612ee54b59792a8b908a372482388ce2f1fVirustotal results 31.15% Heodo