URLhaus Database

You are currently viewing the URLhaus database entry for http://fib.usu.ac.id/templates/files/US/Inv-87109-PO-6D135435 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:52294
URL: http://fib.usu.ac.id/templates/files/US/Inv-87109-PO-6D135435
URL Status:Offline
Host: fib.usu.ac.id
Date added:2018-09-05 17:26:11 UTC
Last online:2018-11-19 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:37:46 UTC to soeharwinto{at}usu[dot]ac[dot]id)
Takedown time:2 months, 12 days, 21 hours, 31 minutes Bad (down since 2018-11-19 09:09:30 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-07Customer No 1015548.docdoc 6f7377ee392a02d97d223dc41df483aeeffa3c450921faa013f10748a264526fVirustotal results 27.42% Heodo
2018-09-07New invoice 1Y3O15074.docdoc e57c0f195888041d1a54af995fa2f9a3641f6fba93a28cf03b9121349ae4d542Virustotal results 32.79% Heodo
2018-09-07New invoice 819ZN04438.docdoc 672a1400ac80f97bae3bdb4f666124a535cb0dae8eb30871d970923a54020c4eVirustotal results 28.81% Heodo
2018-09-07New invoice 6Y7Y37633.docdoc 7091f6f71c7ed5b250e517c2888e9b98471a22b0b7721bc74fa30497a9c46c96n/a Heodo
2018-09-07Inv. no. 886WR1189.docdoc 592280a0fe4c6e0603127a008ce17e3470d2a784812b1df79ab57c528d4bb66dVirustotal results 27.87% Heodo
2018-09-07Invoice.docdoc a200852b665bea31799ef568c2015158ab3db80a5f003123f3882a1f3e84fd02Virustotal results 28.33% Heodo
2018-09-07Inv. no. 1VNQ4399.docdoc 66d7a64a6ea4ea446c65c3f069328e195a3a8897474eeba87c460bad66308523Virustotal results 40.00% Heodo
2018-09-07Invoice as at 07/09/2018.docdoc d1dd9ad72089f8e28c897b4a57bb0f30faacba3dcd0a781030a37c15081578abn/a Heodo
2018-09-07Latest invoice - 270870.docdoc 0943d3a8f5ce6087b3a93abd1f07abf7026ecc40a04bf78dbbd1c00b47eeb544n/a Heodo
2018-09-07Latest invoice - 718494.docdoc 506cf4952d053b1cdab6160a95859552eea61e957c6386d349fb798d708a3fbaVirustotal results 40.98% Heodo
2018-09-07Month notice.docdoc 1c8a83eea94fe2d1616f2e59adc863cb9b516a50bd828853a2211a7cda51c1a8n/a Heodo
2018-09-06Accounts - Invoice.docdoc 714504738e9fdc95addfb3a84ae155eccfc38fb39c3ac13108d3af5a68b9c15cVirustotal results 36.67% Heodo
2018-09-06Invoice Confirmation 0399893.docdoc b17d0d77d9c437efc7cc67b71be0bd8c30eb64c4161698b8145d45560d06881cVirustotal results 29.51% Heodo
2018-09-06Accounts - Invoice.docdoc 2a255834d890d8c82125c3701f929fbedabe2093c81e604d53621b83de0c509cn/a Heodo
2018-09-06Outstanding invoice.docdoc b442b99ee267f30b93ed6474dbe56b8db6b0274857febc8d0a619414a8a75f71n/a Heodo
2018-09-06Final notice.docdoc 3674df1d3b0a673b80a50f176d5fb241d5ed82675be0dbd6acf7a5fdaec4edabVirustotal results 27.87% Heodo
2018-09-06Invoice.docdoc 533a902f789cedfc4b88b0dd1493bb0d8bc736b4b333f9492f1667f41632113aVirustotal results 50.85% Heodo
2018-09-06Final notice.docdoc 70b60b50d027b2fd5f14b0233dae6a4253f62ecb9ff98c07b35f4fde3d55f405n/a Heodo
2018-09-06Invoice as at 06/09/2018.docdoc 749f28c3773f38eb46266ef2a612253ac868255883e99a7117ba93790fed7831n/a Heodo
2018-09-06Outstanding invoice.docdoc 96b60ded9ee0e8bd55ec5d1b4c34f3e0eea61e0bbaa8fcf193fa6a511d6616b4Virustotal results 46.67% Heodo
2018-09-06Customer No 192273.docdoc c0b8bd18ebe466754287750a2c21807e2f1438c32902df92490a84d71d5b772bn/a Heodo
2018-09-06Invoice # 07A3714.docdoc 1c7ac3f0f213a6628455433131b5673c84746fb55b37036642d381d3333708ben/a Heodo
2018-09-05Customer No 360737.docdoc 20b9108674f61c9c77765f5c63ae759185eb5af223570f84e4394e7d7e74b620Virustotal results 45.76% Heodo
2018-09-05Inv. no. 5G5N8046.docdoc 6a7368001187db20be0d83e0e450f06ee3968ab147db4be40241bafbd5f25a93Virustotal results 36.07% Heodo
2018-09-05New invoice 311LJ19692.docdoc 76c4ef2bba3eca811278e1f79b953777c61a1ce476cd371cf4192e22bcdacf6cVirustotal results 33.90% Heodo
2018-09-05New invoice 7NL18186.docdoc 8bd8c360df04712d605109a488dc25201c9294d4872c8682ce67bd7fae3e9a33Virustotal results 32.20% Heodo