URLhaus Database

You are currently viewing the URLhaus database entry for http://ft.bem.unram.ac.id/wp-admin/common-box/1472931-WQi5xHN2zH-profile/IUTAcbfrRQ-lh185J613vvG8K/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307264
URL: http://ft.bem.unram.ac.id/wp-admin/common-box/1472931-WQi5xHN2zH-profile/IUTAcbfrRQ-lh185J613vvG8K/
URL Status:Offline
Host: ft.bem.unram.ac.id
Date added:2020-02-03 23:02:07 UTC
Last online:2020-03-08 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-03 23:04:04 UTC to azhari[dot]hasbi{at}unram[dot]ac[dot]id)
Takedown time:1 month, 3 days, 1 hours, 0 minutes Bad (down since 2020-03-08 00:04:04 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05Rep-47670.rtfdoc 29ab65d0d310cded17a3f3813b2aaaa5ccf8cfd47693806ee9afd63cf5815090Virustotal results 26.23% 
2020-02-05Dat-2020_02_06-243673.docdoc c1d36e9aab2030f23a10178cc432f92255b74c7e2382840bbae1ad7c099e97a9Virustotal results 26.67% Heodo
2020-02-05LIST-O6382.docmdoc 23f4a774007e2fc64a2824e5973bb695a64667d8d832fbc29806976dad67d7f7Virustotal results 26.67% Heodo
2020-02-05doc 20200205 4908967.docdoc 47ca3de0e80a4e9571311ab0b2470ecc29d18c990b063b57aef1818e5a3c260aVirustotal results 26.23% 
2020-02-05INF 20200205 9223.docmdoc b03e332d75fae1c213d41742abe758225f46a5ae68755f6d57dd3cb44326312fVirustotal results 26.23% 
2020-02-05dat-2020_02_05-473.rtfdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05inf_IUO77363.docdoc 4bda34084014e21ceb2db8fb9003f36f4b3a7bd5a8bcfb9b1badbf13529a6d84Virustotal results 26.67% Heodo
2020-02-05REP 358007.docmdoc e9de053b8046e662771b320b25a49cd709591ac896fb6bd4c324ba0b13f37b35Virustotal results 25.00% 
2020-02-05list-NK683.rtfdoc 6228be42f808ff1c2d59dc6df839b24c07a9e9640fffea33d21e69f3b2765a69n/a Heodo
2020-02-05list_NN84581.docdoc 08336d234edb1789ed3461c74e099d408f6a8926e23f9a2b38e210936edf765dVirustotal results 24.59% Heodo
2020-02-05Inf-2020_02_05-KV87524.rtfdocx b0cbefc353db1c65edbf8b0934dd40cb3e036b1cc2be367d2d5f1ac7e95ce342Virustotal results 34.92% Heodo
2020-02-05rep WBJ6094.rtfdocx a464fbbd0fd6eb2e09bb5c04dd46379d3cf1c4f67eeb3f4e9f0b9f7896a2192fn/a Heodo
2020-02-04REP.rtfdocx f189891eacbacefcd510376ad44060a48962b25cfabcdd82b7845acdb512bab8Virustotal results 30.65% 
2020-02-04Mes-2020_02_05.docdoc 6464ea34b63546f7d2cdcb780b772b1250731bd38c105c2feb70e0928d49b1abVirustotal results 32.20% 
2020-02-04inf-20200205-1059.docdoc 3e807f7cb48c71df4ce8ba0a0024238ec14712f1e68e7d0c959ab376f2fbd524Virustotal results 32.76% Heodo
2020-02-04ARC_1516359.docmdocx defe55c9dc26d0ae8ff07ac7bfa3e4b03c672b69761fa507e15b5715ead2abc4Virustotal results 33.87% Heodo
2020-02-04Mes-440.rtfdocx 226e3d9397801a0c20fc12e65373887d6b8e32d5d47ea818a8b891be4513e330Virustotal results 33.87% Heodo
2020-02-04rep 20200204 09694.rtfdocx b652230d0ab5eba2fd05573b7ef10013f6563c1bb9f64d5f5106b15cc8a5ade7Virustotal results 31.75% Heodo
2020-02-04dat 20200204 3099901.docmdocx 265e4a2697fbfecc43edb76419d9e4a8928492d01b548cd7d6804226d6b2a593Virustotal results 37.10% 
2020-02-04Arc 675721.docdoc 8abe3476f2e6ec41653192f2adc6b6095371ddb2fa46044e4e8644c6e5d9694eVirustotal results 36.51% Heodo
2020-02-04Mes DHC833968.rtfdocx 167323f590c8eea01e897581a3de8e00606c176ff6518fd3ac0a3d64dd2e7d9aVirustotal results 36.07% 
2020-02-04Inf 496.docdoc b71394268acf3acca757143450d5ccc9030bb60cd3e5e9e3245f81fa1b63e757n/a 
2020-02-04mes-20200204-462.rtfdocx 3455fc14bf4bc55e2cd1a0d3e6ba9f195bd43d0a44099f3f23cb2c9b95310140n/a Heodo
2020-02-04Arc_20200204_2777.rtfdocx 7866c794e416ef1f3bdbf8d29370390f025c8846d1b4e5d61b2c0b74daa75508Virustotal results 34.92% 
2020-02-04file EG38120.docdoc 492eaa8d97a0af93ff3a9232d9b8be1e475cd9376086354471e1bca5055b5716n/a Heodo
2020-02-04Doc 20200204 LA66743.docmdocx 002d694ef8bf683023d2285a4a16c1673c4ac35874c13d7cfd9c9dc9cee5854cn/a 
2020-02-04LIST 20200204 9806459.rtfdocx 028f4c2dbdc1cc4dcc34a7dd5f190ca34075756f22fefa208b992649fedf8c14Virustotal results 33.87% 
2020-02-04DAT_WIT4855.docdoc 7769ae1cce4e29c3e8bd982600d46a07804c1f66a2772bf00ea100aa24c227baVirustotal results 40.68% Heodo
2020-02-04rep-58580.docdoc 06ef3b76fdfb2eccd0a672a1023ffeff68a0dea6d2a4da527eaa596842391fc1Virustotal results 38.10% Heodo
2020-02-04Rep_PW100.docdoc 0c5326e304b5b23196b990d4ba1000e7a34150acbfa3b3cd8aaa35a12f124e26Virustotal results 38.10% Heodo
2020-02-04Arc_JG476.docdoc 821d5e01c6a22bf01f87a2cc063615e17a74dd2599e21bb6ec2de779f77c8d08n/a 
2020-02-04inf-2020_02_04-HU338.docdoc b5bdbfe46cbe25168c809c0da1cd3018bef7e7821ead2808e7b22f4a01d76a34Virustotal results 38.10% 
2020-02-04Doc 4551375.docdoc b0bb80de572b15a0b0de99bed596703ce05859027b0b5a001b36eb8927608155Virustotal results 35.48% Heodo
2020-02-04Arc_2020_02_04_45261.docdoc 25108aa43bad658dcec2d751b81cfe9598c164de1f28ba8e0d926229828d88d4n/a Heodo
2020-02-03Mes-20200204-BOB84230.docdoc de283e104e0f841b1dd615a6400f671afa7271b94c0b3cece3f4e5dc244cda9bVirustotal results 30.65% Heodo