URLhaus Database

You are currently viewing the URLhaus database entry for https://pai.fai.um-surabaya.ac.id/cgi-bin/invoice/379800/xdb2tei-7226/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:754475
URL: https://pai.fai.um-surabaya.ac.id/cgi-bin/invoice/379800/xdb2tei-7226/
URL Status:Offline
Host: pai.fai.um-surabaya.ac.id
Date added:2020-10-27 03:50:10 UTC
Last online:2020-10-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 03:52:02 UTC to pti{at}um-surabaya[dot]ac[dot]id)
Takedown time:4 hours, 38 minutes Good (down since 2020-10-27 08:30:07 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27invoices 248 & 3966.docdoc b171e32307062d678cf65b634b1c711ac00b69ce2762db5e486e17858686ed6cn/a Heodo
2020-10-27VE9059323481HL.docdoc 1abc9cb4b42aa993827e65cc07634e361063327ecfff66f291760b54d91dcd80Virustotal results 33.33% Heodo
2020-10-27Inv_005534.docdoc bf919cafed94b4925e4ffac8782e0f11c045d10d802a806e21dc77e6ba92322dn/a Heodo
2020-10-27Invoice #2977.docdoc a87c03b72e4bfc12901f263c082a8116384d91ee5d14bbb51d2d5d513e3be595n/a Heodo
2020-10-27Payment status.docdoc be38d405f6ea9e49d7be5ef0c7f75b7c3c8b201ed03af92b15ae0f6f284df534Virustotal results 33.96% Heodo
2020-10-27invoice #50273.docdoc 02061a2f03b777124e5d2d13a1a6b49e10ee33cdca6ecb147af00497ee595677Virustotal results 50.79% Heodo
2020-10-27form.docdoc 09698f8941fab0d6f62dce908249dd566ea7d661cfb8307d4fac50c9dd4b36abn/a Heodo
2020-10-27October Invoice.docdoc 5e371b305eb74219f8f11f61a0e4d713ca73e7e21a7b8205627e01639fee8a73Virustotal results 50.00% Heodo
2020-10-27Form.docdoc 1aee40969c1479d8943cfb37afa6c61799d93f91926a707fe59c095c4ca70555n/a Heodo
2020-10-27Payment status.docdoc cf4cce1dd4d0e37f8feaad89775e06c289a4386524352438ab05701181faa95en/a Heodo
2020-10-27October invoice.docdoc fe12f4901b4c328ea0129d5b5637b243133f923032b75cae8360b06db8c7716cn/a Heodo
2020-10-27Invoice #50523.docdoc b52206a6519f1e314af1c195541e3e199149e2f390d1828c1702df72f0890ecdVirustotal results 49.09% Heodo