URLhaus Database

You are currently viewing the URLhaus database entry for http://elektro.untirta.ac.id/_vti_log/parts_service/4oSanURjgyI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:548926
URL: http://elektro.untirta.ac.id/_vti_log/parts_service/4oSanURjgyI/
URL Status:Offline
Host: elektro.untirta.ac.id
Date added:2020-09-17 22:33:09 UTC
Last online:2020-10-12 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 22:34:03 UTC to support{at}easyway[dot]co[dot]id)
Takedown time:24 days, 14 hours, 57 minutes Bad (down since 2020-10-12 13:32:02 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19Dat 2020_09_19 93645.docdoc 03caf29484a047db9c68e15e6117f665c59b1cc6ea7cdacba9042f80149861b9Virustotal results 22.03%Heodo
2020-09-18ARC 2020_09_19 K02696.docdoc d28151cda4058aa8e8c1175ab6fea760c7c6812f758570a50fca1ad2b52eea2eVirustotal results 22.03%Heodo
2020-09-18Attachment 2020_09_18 5754298.docdoc cc0f522275048b3b4279cee69baf8e05dae990c9063726ca6f1046e9b881bb7eVirustotal results 22.22%Heodo
2020-09-18rep.docdoc 7962c53412619716d3f3c55bd0ec83e7678990f635cfa95e918f3cf6ae33d5ccn/aHeodo
2020-09-18File 880790.docdoc d1b8c76a762ca9f345087a55694e8247d9e816190093ae1cd19a51d990661aden/aHeodo
2020-09-18inf_2020_09_18_556.docdoc 36919712f986c81feab840bee68faa72d3c7d9ba61a8cfd186b6b1b1190f3277n/aHeodo
2020-09-18DAT-GA8488.docdoc bc823a6f2b911b1ac1a2c9bd1e0ceacc75e9d913e41f318def70472ef315536cn/aHeodo
2020-09-18LIST 18591.docdoc f764c5a489ae94b2a089f5333c8911cc6f4584805203a09110346af8f427a5ccVirustotal results 25.00%Heodo
2020-09-18file_2020_09_18_373.docdoc 1b9db1af32e52d4761c7f112288b8b7bc8c0507a2577a677370fc33b2321ee6cVirustotal results 21.05%Heodo
2020-09-18Inf 2020_09_18 TN8907.docdoc c56f2412e4759fb07fcfaf0e3b30f041c10a86d3514f2e812844f42c23016248Virustotal results 18.64%Heodo
2020-09-18FILE 20200918 0101463.docdoc 1de0cc359d911b8ea7f0d8e8e345d5d3b0565076570c85494e6e4ea147f271d3n/aHeodo
2020-09-18Mes_20200918_QY68362.docdoc a4860edee89892f911d11e6b19df9eb316ac69dc52771821196d58a546aee8f1n/aHeodo
2020-09-18LIST-2020_09_18-UMI29507.docdoc a8fbe20181a901e4ee77e91e558cb97c24abdf0654a81d254124fc9dbcfce07an/aHeodo
2020-09-1826512489 M5882.docdoc 694a675405bba3ed747dd1bb25ef59a25081523c6ded90281559d95d2f262737n/aHeodo
2020-09-17INF_20200918_43649.docdoc 5b75b8ef50bfcbbb530308fd7bf20ca6fed376e9e93b36bfffc74d7917457d49n/aHeodo
2020-09-17file_2020_09_18.docdoc fac05b7ef1455e22097b936c48496ba95620364be0aea7125fce483d1bcd7849n/aHeodo
2020-09-17FILE-VJ261678.docdoc 57910dd6516ac947fca972b389bf12d25f16ebc65daac2f6315bfaf6ef7518cdn/aHeodo
2020-09-17FILE 2020_09_18 RE5370.docdoc 578663ca789cbb8f68ad4c1a55a609f0cfe21226ef04719d8fe894db5932f181Virustotal results 34.48%Heodo
2020-09-17Attachment_272.docdoc 03d25f99b30809ea158b778215811e2b6f77ce324adbf5ee133e0bddc5a5089aVirustotal results 34.43%Heodo