URLhaus Database

You are currently viewing the URLhaus database entry for http://fib.usu.ac.id/templates/954038PSKNTNOK/PAYROLL/Business/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51060
URL: http://fib.usu.ac.id/templates/954038PSKNTNOK/PAYROLL/Business/
URL Status:Offline
Host: fib.usu.ac.id
Date added:2018-09-03 17:00:08 UTC
Last online:2018-11-19 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-09-07 11:37:46 UTC to soeharwinto{at}usu[dot]ac[dot]id)
Takedown time:2 months, 12 days, 21 hours, 33 minutes Bad (down since 2018-11-19 09:10:52 UTC)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-05SWIFT #800KFBQCP.docdoc 4ce80b20371042e1468aec668ffcad7417124d6a1c4bdd0cb296193c199d84d6Virustotal results 32.76% Heodo
2018-09-05BIZ #9001022U.docdoc 517cfa5dc9f8a53bbe7d881d08cf89f179c90d15dbc7ab323f1f92f893449d21Virustotal results 33.90% Heodo
2018-09-05PAYROLL #081780STBEVIN.docdoc db3cc7177e7a94494bfbe8169aca696977a8b6982ab0df6ba43f5de8ec7b0734Virustotal results 33.33% Heodo
2018-09-05SEP #312807ZOZ.docdoc 344439c6ff4aeb852d73ca9e677b830ec6617e53e3aa1ad9eb479200876e6de7n/a Heodo
2018-09-05PAYMENT #996BL.docdoc 2ada1a2d3af4138a9d30760ed7b6d0610fdacd99ce7e13cf0c5b94856af63185n/a Heodo
2018-09-05BIZ #8ZDNQ.docdoc e466888c8e21f43a235e0ca2ded46371e5c9120d2a8cc5f334149074e3150eb5Virustotal results 44.26% Heodo
2018-09-05SWIFT #18TDT.docdoc 5460a6926076019f56ae0a7f38de3e20a19522807ec720cfb8d64f85de6689a6n/a Heodo
2018-09-05SWIFT #015072IUVDS.docdoc 5f391b39ad87d1e3994701e5c68b21d10cc1b8844ddaa31de2460c1239b09e6bVirustotal results 34.43% Heodo
2018-09-04PAY #508UENUVL.docdoc 66f8fcc2dc5ad76b8818676f97037f3c0decf466abb0a97d14c468160adc52b1n/a Heodo
2018-09-04PAYMENT #548637NV.docdoc 5dfca212c007ad7b2b0f2e6fd0323a334b9a07cc304f3e74abad037450eac244Virustotal results 31.67% Heodo
2018-09-04SWIFT #3039096Z.docdoc f65b60f709c2b6674fe316d9fe47bdbf2a0f0939dd9e04f7a4353a52bf27ffadn/a Heodo
2018-09-04SWIFT #725GQPHZ.docdoc b0eb2f583b73e7dc9c62fcfd8b7048fa5d3284526fe78a8ccb021c43022d6e3eVirustotal results 31.15% Heodo
2018-09-03PAYROLL #7939DHZRYS.docdoc ee25a894f4d201172d77bcf4a59f55e1a85cf4aac468c50d824ccc7bc9f4cb58Virustotal results 45.90% Heodo
2018-09-03PAYMENT #86YN.docdoc d97f4f0517fb72880edf1331430a8f4e8d8c1e861e1b3480e84d6552ccfdcff7n/a Heodo
2018-09-03SWIFT #9292WAO.docdoc ac6b363f69c44a1a7fc2839354a67bf3bafee9b85a00f2531d7433d5b6de6f15Virustotal results 36.07% Heodo
2018-09-03PAYROLL #7L.docdoc db4d0da9e5c028ba0e16c00b02ead5aae9259e3f367916ff8b899683f93490den/a Heodo