URLhaus Database

You are currently viewing the URLhaus database entry for http://fib.usu.ac.id/templates/Download/SV01296648899G/Aug-06-2018-3737548/ST-USEAS which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:39354
URL: http://fib.usu.ac.id/templates/Download/SV01296648899G/Aug-06-2018-3737548/ST-USEAS
URL Status:Offline
Host: fib.usu.ac.id
Date added:2018-08-07 06:05:19 UTC
Last online:2018-11-19 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-08-07 06:13:51 UTC to soeharwinto{at}usu[dot]ac[dot]id)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-08PAYMENT 647JSH Aug-08-2018.docdoc df77f9b54e2f7009adbcc2f03c2868a01738de43b18f61e68be708845b8c5c9fVirustotal results 25.42% Heodo
2018-08-08WIRE 2DFOXSJ Aug-08-2018.docdoc ed1d3ca332d76f9181d652f9a3dec9506876838bbf5507ea766390826d3f84f8Virustotal results 36.67% Heodo
2018-08-08PAYMENT 3723772ZLLTQY.docdoc ca90ee3ceb6b5f53c97e5621978522340940c65ff05b26248b391c4971d098a9Virustotal results 36.07% Heodo
2018-08-08ACH 8465RSQVCHU.docdoc 904171c20a36669fe9ee06fac73eb36dd9d390361e3d7f490e502c370f72cdc6n/a Heodo
2018-08-08WIRE 56203D.docdoc 6ac0e66ce6079eb7c77aefa7af63fbde6d61f4a4ab2d44b7fa92d9ae3e871cfbVirustotal results 33.90% Heodo
2018-08-08ACH 905229AVKFPTV.docdoc e1c6a8a81e869ed96d6afeafb3eca1ed05e0eadefe60f7e0d45358a26885f509Virustotal results 34.43% Heodo
2018-08-08PAY 0117585JKP Aug-08-2018.docdoc 7bc9502b897961a06d9489192d04939294b56b2982647ccc80db12c5caefebdbn/a Heodo
2018-08-08PAY 178700K.docdoc 465392907ac0de1068a5b4cf9019e7a5a6d2f4b65c301c261842d62c332a42fbVirustotal results 34.43% Heodo
2018-08-08PAYMENT 29GIKJEQ Aug-08-2018.docdoc 744feeebd9a9cb0ecd36f45e5ef235ae78717c7bb41f9b8ff48e20c9ea4e44b9Virustotal results 32.79% Heodo
2018-08-07PAY 35JIBZ Aug-08-2018.docdoc 4dda9e18a7ee5a88d9b18cce544dd6d47b818f953e4d2969b8787035ebbe8465n/a Heodo
2018-08-07WIRE 111S Aug-08-2018.docdoc f83ed0b8740d63b8e020df41c168e9a535b3af5bc537c1a4a56871ed63470e54Virustotal results 32.79% Heodo
2018-08-07PAY 6295157KJRFM.docdoc 4803a9181557f13c4b8452f9776a2f585175ff9d687b26fc1ac8b8fb5009b68fVirustotal results 34.43% Heodo
2018-08-07PAY 930637OQOOHK.docdoc 7afd709cf8761dbf7ba69efec924f25d96186c32216c7d0790871ba5c49f74aaVirustotal results 33.33% Heodo
2018-08-07ACH 95649VOH.docdoc b77569cf7ba95d471ad9607ff2bab4ffce00de094b82b5811d428cc735fa85d5Virustotal results 31.03% Heodo
2018-08-07WIRE 9422366QKCFY Aug-07-2018.docdoc e633b6c6918dbf42fb5ebe1879d34721ab885240a7578c7e07e0b2f423a25f20Virustotal results 32.79% Heodo
2018-08-07WIRE 9241MDY Aug-07-2018.docdoc d93f93e5b81ba74a4e035b11fb4129fad5a036ebd0547d818d90e0e9752716b9Virustotal results 32.79% Heodo
2018-08-07PAY 2VNQAQKN.docdoc 9b44aaea9e7d19b5287f6bb14cff0b64e23703f9c7164224623fea615cd2941dVirustotal results 32.79% Heodo
2018-08-07PAY 957DGEYVE.docdoc 0dcbf20f9f005505fafd4bcc854f06b90d137bf51b69d7582570a4135b5ac8d7Virustotal results 34.43% Heodo
2018-08-07ACH 3MNAYX Aug-07-2018.docdoc e7d99cf53f2328ba4585028e7bb9d4f347419d4f9c8730371eec4842009ce8a9Virustotal results 32.79% Heodo