URLhaus Database

You are currently viewing the URLhaus database entry for http://farmasi.unram.ac.id/gatau/closed-disk/p9z9oz-qes06v4de-space/u7lXevvkiDA-yd9Msexnu7a/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300072
URL: http://farmasi.unram.ac.id/gatau/closed-disk/p9z9oz-qes06v4de-space/u7lXevvkiDA-yd9Msexnu7a/
URL Status:Offline
Host: farmasi.unram.ac.id
Date added:2020-01-28 15:25:05 UTC
Last online:2020-02-05 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 15:26:03 UTC to azhari[dot]hasbi{at}unram[dot]ac[dot]id)
Takedown time:7 days, 15 hours, 50 minutes Bad (down since 2020-02-05 07:16:28 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30Rep_S5218.docdoc b14de0a4835378a27f6b3a4273b2ddb67180fe1cf3c6068ef740a8a0a74d29dcVirustotal results 30.65% Heodo
2020-01-30Inf.docdoc cd3214c911c1d942daf6c996111cd99097c00e5fc450d39c2abfdb45c27658c8Virustotal results 31.75% Heodo
2020-01-30doc 2020_01_30.docdoc dbafc866496ce6edbe3c92ff5b13a847d53b29e211c6061de2f2881c8301233cVirustotal results 26.98% Heodo
2020-01-30DAT-2020_01_30-YMT912.docdoc 6cbdcc0ba57b84c01a9533651f01585aee4755d88da9396ea266f936201496c6Virustotal results 29.03% Heodo
2020-01-30MES-20200130-461.docdoc b6033387e8a30e0590f8e152c6234c360412bd1687400e315384a939a1b6071aVirustotal results 28.57% Heodo
2020-01-30rep-20200130.docdoc 093fe06865cc5cd449e9684d621efaf181505881f5e0e818b0ec9c4459ef1ba9Virustotal results 22.95% Heodo
2020-01-30doc 20200130 7583854.docdoc 23b0933587b2ce021d44e764dcdfb9961d967b9e9490d154457df7e420cf9fa4Virustotal results 25.00% Heodo
2020-01-30REP-2020_01_30.docdoc cbfd00a796bdd447134f7dc1f38823e8e2eefb7075068cc197ec67c044ecfc24Virustotal results 24.19% Heodo
2020-01-29inf 20200130 G599.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29File-2020_01_30-5312106.docdoc 2c7a2ffff7a4a2fcb7a86235dafda3b02ce67330155e00a22408d6c14b2f5cafVirustotal results 40.32% 
2020-01-29mes-884.docdoc de39c0b0ba341eb6a6c1cc3bff5a3dede93907976a77563396df5165f422ac7fVirustotal results 33.33% Heodo
2020-01-29mes-20200129.docdoc 7e8c0e91d30b485bed7963d9d3169c243edb3f5f2ce5e8049df4731007ea4d61Virustotal results 32.26% Heodo
2020-01-29Rep_2020_01_29_YP5082.docdoc 49725f6641477d5fcdc1933e66eb652922a1e1264277a6aef8069967eb0084f0Virustotal results 30.16% Heodo
2020-01-29Doc_2020_01_29_TI436.docdoc b09c8d39fe17d600ac2beffd9540076f55d944b41ae3c11b26600252a272b3ecVirustotal results 26.98% Heodo
2020-01-29INF-20200129-NAR189854.docdoc a6f8d6e5f80b47b55146e82c61a78c5ed8c451bcb68d157dee574d02c768ba30Virustotal results 26.56% Heodo
2020-01-29MES_2020_01_29_IZ359.docdoc ec9b05ca4512e2e594339751e698ee57b1373c749a8c8b26cbe5c79dc1e978ccVirustotal results 26.98% Heodo
2020-01-29rep 20200129 3931.docdoc 7fe7d585439b5c35ae237be440c87a62cc89bfb0bb98bceb800b85b6aefc7ce6Virustotal results 27.42% Heodo
2020-01-29arc 2020_01_29.docdoc 02e02e6f3d5f2447a5269982bfa0714b129e54897d7616443ca03430d0a3188bVirustotal results 25.81% Heodo
2020-01-29inf-034.docdoc 2c68f8e2764dd94c2229034f644bf7cb24cd34b1fa153e999d321e0e4eb8e73fVirustotal results 24.14% Heodo
2020-01-29Inf 2020_01_29 168.docdoc a1245dc00abc837e5b912c2aab2cc8eb34eb70db4bad71991edb4854fccadfb9Virustotal results 24.19% Heodo
2020-01-29Arc 68121.docdoc 7c22eab322ac6b786498c54df9abb223c3466203f681028b1023147f081fd6can/a Heodo
2020-01-29Arc-2798897.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29doc TA444739.docdoc 085777a85dd9b9d62ecf918d0cda586ecae8d0b32af5aa6182d85c77a8a571fdVirustotal results 42.86% Heodo
2020-01-29Mes O4997.docdoc f5c5c5efd56a06272577f6aa8fde6fe22660095ec9332d7449f3e0769fa11b8eVirustotal results 42.86% Heodo
2020-01-29FILE-20200129-82549.docdoc d0587297f7b5699b364592f59c0d93057b42defb42c714d6381d54a6142953edVirustotal results 44.44% Heodo
2020-01-29arc.docdoc 5ed01ecc76724ef8dff654d4ef2b359c600c6dd3da2481677304b851d0c752b7Virustotal results 43.75% Heodo
2020-01-29list PC74656.docdoc 24feb6df1e8f6c53bd9feedc048edbaa84e854f4accbd7fd64e8c4c74b2de5b9Virustotal results 43.55% Heodo
2020-01-29REP 20200129 142.docdoc 705a21a458e18ec2353f1141cd6971cd6ffe76398c6c0bffea9c4f3e2c370c87Virustotal results 39.68% Heodo
2020-01-28ARC 20200129 UUJ6325.docdoc 522de927311fdb0ba76d51ac880c13fa8dce461eec5a120570a58e27fc82fa06n/a Heodo
2020-01-28doc.docdoc f2a6a0283ff20ad3d0855ce7825d84920a0a27c55825a5a5b9ba91408388a402Virustotal results 41.94% Heodo
2020-01-28mes 155.docdoc d92bc4efa28b232e6331a4e9b5f75992659ad3e64268f5adac60ea14f9932f5dVirustotal results 36.51% Heodo
2020-01-28REP-2020_01_28-XSB316913.docdoc e6384df1ef6040795e8d6521f54723cd118a6b6cd4a007f0ca96e3558f55b81bVirustotal results 34.92% Heodo
2020-01-28Rep_2020_01_28.docdoc 76288b03aada28f313d41a8856e42320372dfc03b255335b3d8c0427cb01c4a1Virustotal results 31.75% Heodo
2020-01-28LIST-20200128-646.docdoc 905563c6be86ed6e853e1f2bc9f4cdffa60c74647a96e1fe871a53a585ae3a10n/a Heodo
2020-01-28MES_96249.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28FILE_2020_01_28_O84580.docdoc 0d61dbf9684ca83b5af462a91ffbfc24afab710cb30782da34d1c34e6f4fb918n/a Heodo