URLhaus Database

You are currently viewing the URLhaus database entry for http://fib.usu.ac.id/templates/44ZBCINFO/FEY59759518830BAADK/Aug-13-2018-1006597/VB-QRBHP-Aug-13-2018/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:42526
URL: http://fib.usu.ac.id/templates/44ZBCINFO/FEY59759518830BAADK/Aug-13-2018-1006597/VB-QRBHP-Aug-13-2018/
URL Status:Offline
Host: fib.usu.ac.id
Date added:2018-08-14 04:46:04 UTC
Last online:2018-11-19 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-08-14 04:52:05 UTC to soeharwinto{at}usu[dot]ac[dot]id)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-10-15WIRE #7731121WLNSEBEO-Aug-15-2018.docdoc 7a868240e5191e4b8970f35d6ceb586c504bff513b776b1964f8c3f5b5f084d3n/a 
2018-10-15WIRE #7731121WLNSEBEO-Aug-15-2018.docdoc 31df57e53e4e21a92305cd08a7231d28612bae77c24a107abb4929448bae0ba8n/a 
2018-08-15WIRE #7731121WLNSEBEO-Aug-15-2018.docdoc f3f4903652a9ff6224f8d9ae920e5b99093b3c110c51bcc16a9ae31b32af9004Virustotal results 23.73% Heodo
2018-08-15WIRE #7654PINUK.docdoc 824b994e79209479f239099b9c368aaff46a6fe2ce5a047d8b8cbaa093a9fdaeVirustotal results 31.03% Heodo
2018-08-15PAYMENT #32377J-Aug-15-2018.docdoc c47f17a1f0161b5d502115b0027e18ceda36d53c1b3f1f8f1c46afc242ce8d0en/a Heodo
2018-08-15WIRE #7544E-Aug-15-2018.docdoc 72a9605fb3bb77cde5b3fb2d1355df6707e0fb3c7fe4d0ee20e561354234d15bVirustotal results 37.93% Heodo
2018-08-15WIRE #075359N.docdoc b3780348a997bf9644df511fc09819640396ae7b5934775a7dae92d1453b9f74Virustotal results 36.67% Heodo
2018-08-15PAY #4771ELYDHNS-Aug-15-2018.docdoc db0486e7fe13763954972e8b29e104d2b9b6f7070f4638d828b707a63c1ecf2bVirustotal results 35.00% Heodo
2018-08-15PAY #0HIQ.docdoc c9f4fdf390dfac51bd78635013c2129bf6edc1e81624a763dee822fb6ce92352n/a Heodo
2018-08-14WIRE #1185FTDHZBZ.docdoc 508031ccd8296213aa5df40be3710cf5ccf0b3202b9f4e16f1e0d1e60efdf268Virustotal results 30.00% Heodo
2018-08-14PAYMENT #08889G.docdoc bc4381b76ef10982d2f32f07816b5d3e87ed6b4ead245d8c830424422e7bc06fVirustotal results 26.67% Heodo
2018-08-14PAY #27643VWFAE-Aug-14-2018.docdoc 75c75abfb68fa9ad3ba70008aa74974e0125be70764678d86e51f1ca37d0d918Virustotal results 28.33% Heodo
2018-08-14PAY #551NXCGATJM-Aug-14-2018.docdoc 0cac37127b1e7c37b8bf7890b5e7b30d2d4254e3b34ebe9c55bc702373104f3bVirustotal results 28.33% Heodo
2018-08-14PAYMENT #5RN-Aug-14-2018.docdoc 200f9ce2b352f4cadc07b595bfd5687cd67a942892ea333eec4cf3fe2636874bVirustotal results 26.92% Heodo
2018-08-14ACH #3J-Aug-14-2018.docdoc cdc86d9833b498b8b5b1675f86a064cefe95973b766e264cdb892275a2b2efb6Virustotal results 29.31% Heodo
2018-08-14PAY #4685315AQ-Aug-14-2018.docdoc 624cd190286fdbf40b32768f2fd330f7ba4ec4824a38fef7894d24708c52411fVirustotal results 32.20% Heodo
2018-08-14WIRE #042892GYW.docdoc 4ed13b5c46a1f58dd71eadc6da39b9d89dfe3291a99b45aaee64eddb85fc4ae6Virustotal results 30.51% Heodo
2018-08-14PAY #9393CUIR.docdoc d9b3efe80a0736cdb64cd29975e21a03e694820936b9798b2de4092cdff10662Virustotal results 32.20% Heodo
2018-08-14WIRE #4PLBMQE.docdoc 6bd1dab30b58fecc8e8e5a1c59e4c16651f28fd5e77c107f47b54b61e4815ba2Virustotal results 26.67% Heodo