URLhaus Database

You are currently viewing the URLhaus database entry for http://lpm.unublitar.ac.id/test/Documentation/svjzo2k0ju/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:446011
URL: http://lpm.unublitar.ac.id/test/Documentation/svjzo2k0ju/
URL Status:Offline
Host: lpm.unublitar.ac.id
Date added:2020-08-28 12:28:37 UTC
Last online:2020-08-29 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-28 12:30:03 UTC to abuse{at}Qwords[dot]com)
Takedown time:13 hours, 18 minutes Good (down since 2020-08-29 01:48:20 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-280639527316404693111505.docdoc 91729212a1e8ce3d8a7de3848bc5b330272540ed0d91da03b34e3542ae32f787Virustotal results 28.07%Heodo
2020-08-2854447781033058632723200.docdoc 45c6cbf3a848206d33f3a4d92ca9ac6f3511b39227d46e433887c00384ed6f56n/aHeodo
2020-08-28REP_MO8854168896AP.docdoc f5b03a311135b32ed372590430479a35b0e7c1538ffe7e95f60baf40732f350dVirustotal results 27.59%Heodo
2020-08-28INV_C2XH2T6F9BLJEMI0.docdoc 6fb504f2fd1966b7eb00f0a9cdcbd5fc4cedbc4bc50d5d77702e61460e5230d4n/aHeodo
2020-08-28YSY_080120_BZG_082820.docdoc 425659a7db67434fb846e86eb949e0ae4af1288284cfe1633ebd1229f20a9c55n/aHeodo
2020-08-28DOC_XCN_080120_WLG_082820.docdoc 0c270e671b26e1f67dce64275728bf84ef4f5bb7af9d05b3a934c535d773dea6n/aHeodo
2020-08-280635850108523768964859.docdoc e3ce3a99ec926db991576661b442a60aca41a86fd410508a544257b63a5cb4b3Virustotal results 27.12%Heodo
2020-08-28BAL_57866732.docdoc f4a8c680fd30bfcdeb471e51625dde88c3b97240656b50635930776ac46f3eefVirustotal results 27.12% Heodo
2020-08-2809317911.docdoc ebbbf1104be5c5f4f000285e72aa802cdac327750e71a35a101e4ecac224d1d2Virustotal results 28.07%Heodo
2020-08-28REP_394LI0R3.docdoc 74fd5e51184bd860adf8fa2da123bfc7876d06d7ac5007da67eb4a56f54640a8n/aHeodo
2020-08-28SVNA_PO_08282020EX.docdoc ecec70a49cac590cb3d67dc6555fa9351fbbdfa81c00d8a2273e49527baa5463n/aHeodo
2020-08-28OR1166701536KH.docdoc f49d9546a53d5b00619acd8dd32985c7475d25628ab997d7f6160250372fb2dfn/aHeodo
2020-08-285589034719298101914.docdoc 27f491d8699691693a49de0311f599217421a625d6887ef3ed28eab01a99d311n/aHeodo
2020-08-28BAL_796667267832386.docdoc 0cd591e888f747fa51f114956af6c01d36b7e5a352294a21ebb17438d525440an/aHeodo