URLhaus Database

You are currently viewing the URLhaus database entry for https://pwk.ft.uns.ac.id/wp-content/gallery/sei1yiza-00029734/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:938832
URL: https://pwk.ft.uns.ac.id/wp-content/gallery/sei1yiza-00029734/
URL Status:Offline
Host: pwk.ft.uns.ac.id
Date added:2020-12-22 17:02:07 UTC
Last online:2020-12-25 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-22 17:04:02 UTC to abuse{at}uns[dot]ac[dot]id)
Takedown time:2 days, 9 hours, 26 minutes Poor (down since 2020-12-25 02:30:18 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22E7341287668DxJt.docdoc a61add91d1ec99ec85463137cdefd5a4f56e2bc5885b00b4fdb840347ed6ab4eVirustotal results 44.44%Heodo
2020-12-22December Invoice.docdoc 06afa527d491ea89976252a79d12ee284b0b16c44d190f5668a3c541f0aa50fbn/a Heodo
2020-12-22PO# 12222020.docdoc 4b88a84e389abb44331350f8658aa02ad80990f59c8d7dd1cfbabfc536cc6744n/a Heodo
2020-12-22invoice.docdoc a0aa13db6c8109cee5544abb9e28e2455ced6b65a3a34f0b1502989fb24a411fVirustotal results 45.16% Heodo
2020-12-22410335-122220.docdoc d54ba8a8a51f5b139f174c012bb6cb5d21135722e679bbb89e7eebc2c20c1988n/a Heodo
2020-12-22Form - Dec 22, 2020.docdoc e6db5129c4003a3f71604d209d5259c882bf45554568174daebf8c248f99d4cen/a Heodo
2020-12-22PO# 12222020.docdoc c6d8d0a96a53cb9daa207f66116c20fba8be3dc5688f7d3d82adcc5326fdaf85n/a Heodo
2020-12-22December Invoice.docdoc 1dc9c5d757f9cb44653cbffb54a18b1b31dcdd57c7bdfeec27657a1e3a79e780Virustotal results 43.55% Heodo
2020-12-22PO# 12222020.docdoc f817b73b9dfcc5de9d4dbb3e5d797449f155c6f1faa7991e9199de0c9e23c6f9n/a Heodo
2020-12-22Form - Dec 22, 2020.docdoc fcc999c249edb86e0084722fe062aac095e907ba25fad3a1c9065d23982eca31n/a Heodo
2020-12-22Payment status.docdoc 06d3a58c494933212a50a74bc3fec36b14dc5716574b6793f3b41117371cafb9n/a Heodo
2020-12-22Form - Dec 22, 2020.docdoc 2df9d5b2d6e0c788ba630c2fcadfd27aedc488e931c33401567bf11e5307cf46n/a Heodo
2020-12-22Invoice 00wlQfU.docdoc d03fc0905d26be1f4da81d8a867683b6c1a708591d8553a1f6a1a25f88bb0c5cVirustotal results 41.27% Heodo
2020-12-22Invoice #31827.docdoc 4a3df0fb379f1f2d8ff39c331e9c6fa59ce855cd07767ffb53adbdb9d3f9f2d4n/a Heodo
2020-12-22INV #09896486 FOR PO #16605619.docdoc a10813e72a3167974b045bcaad52b2188a5a169b297890ffced02ca74dee7560Virustotal results 40.98% Heodo
2020-12-22Invoice.docdoc 06ddbe2938aad51545764c4525734b4ccb25e47c82ce6ebe975e6ad5becfde91n/a Heodo