URLhaus Database

You are currently viewing the URLhaus database entry for https://pai.fai.um-surabaya.ac.id/cgi-bin/17889/3253504993984/s7pqal5e-73684/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:754499
URL: https://pai.fai.um-surabaya.ac.id/cgi-bin/17889/3253504993984/s7pqal5e-73684/
URL Status:Offline
Host: pai.fai.um-surabaya.ac.id
Date added:2020-10-27 04:00:08 UTC
Last online:2020-10-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 04:02:03 UTC to pti{at}um-surabaya[dot]ac[dot]id)
Takedown time:4 hours, 28 minutes Good (down since 2020-10-27 08:30:39 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27Payment.docdoc ce3db60db8082987dee9dad11780a71f83f6e2de05dd62b1d20ae33371120c50Virustotal results 32.69% Heodo
2020-10-27PO# 10272020.docdoc 1b2042d1d563f44a3907c5adf968483d89094e0db451f9eb410af36521812966Virustotal results 33.96% Heodo
2020-10-27WX0026 invoicing.docdoc c84a48640f526e96f5eb4967469b06129ec91766396ca32ca6d455cfd533a3c4Virustotal results 33.33% Heodo
2020-10-27Form.docdoc a87c03b72e4bfc12901f263c082a8116384d91ee5d14bbb51d2d5d513e3be595n/a Heodo
2020-10-27001773728057.docdoc be38d405f6ea9e49d7be5ef0c7f75b7c3c8b201ed03af92b15ae0f6f284df534Virustotal results 33.96% Heodo
2020-10-27Invoice.docdoc 6bec2d25f21cfd8e028b9be4f3b7dbddd62daa9d0d583a281dce8228e66a5216n/a Heodo
2020-10-27Payment status.docdoc 09698f8941fab0d6f62dce908249dd566ea7d661cfb8307d4fac50c9dd4b36abn/a Heodo
2020-10-27TY8093120881AU.docdoc e921c3eced90ed5ca0b1034f31b7834f18395410b56715c8c74d20521c69f9f4Virustotal results 50.94% Heodo
2020-10-27VK3292818797EX.docdoc ca286e09b37ac73d3f0f4c732859bfb635073af2e14c81db7268955f8f2b796cn/a Heodo
2020-10-27form.docdoc 018ad27bedae4353c841535a731577e512acd0c8e0e51dd38d303f346bb9ceebVirustotal results 50.91% Heodo
2020-10-27invoices 9581 & 4542.docdoc a88734cd5c38211a4168bc7701516a50e6aef5ef20d2b1a915edae23c1b345dbn/a Heodo
2020-10-27Electronic form.docdoc 7025a79caf1e0e05400aa946eea8f0cf6a58638edb662f95314ecf9ce329a37an/a Heodo