URLhaus Database

You are currently viewing the URLhaus database entry for http://akademik.upr.ac.id/wp-admin/NUEpk0o2ztkSL6kukObc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974244
URL: http://akademik.upr.ac.id/wp-admin/NUEpk0o2ztkSL6kukObc/
URL Status:Offline
Host: akademik.upr.ac.id
Date added:2021-01-22 16:28:05 UTC
Last online:2021-01-26 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-22 16:30:05 UTC to noc{at}agti[dot]co[dot]id)
Takedown time:3 days, 10 hours, 8 minutes Bad (down since 2021-01-26 02:38:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-234OHLA2C5.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-22GSCKBLPXUNEXU1.docdoc 377ccf81bc50553f09c559652bad5ec67c73c649cb60ba53cfd01f39a52e5ad2Virustotal results 38.71%Heodo
2021-01-22ERB5SPOI.docdoc d369edd4ee295fafd1231bb5d370fff75a48505360a64708bce6418c7f2974a1n/aHeodo
2021-01-22V2PF00.docdoc 8af280e70fb92f35455e9f18296c0fbaae42288517c6925a9db673a9368e9bf3n/aHeodo
2021-01-2223DVT5.docdoc 26e5e6911e1f51c17316418cb81c5e699c0f986235871bc9e8c1c473c6109655Virustotal results 33.33%Heodo
2021-01-22HO3DM6P45YP5WCG1.docdoc ab6d3be4c24da3e9c1df9e970119843a19dd372e08d3be797ce636117a71cb15Virustotal results 31.75%Heodo
2021-01-22HVOH573DWLWUT.docdoc d25d5d359b01bb46095375c553f2b4ea91e2e4abee77df10d21d6ab08740dc97Virustotal results 35.48%Heodo
2021-01-22Y2CZFDS.docdoc 14f0eae441176623b724e20538f6ac72f501b60f4c5c855b651ca9cb1e9d3782Virustotal results 32.20%Heodo
2021-01-22B55KLJE01FDT3R.docdoc a1714164bf96046b86ee335216b926f51c376447578ad9dc401301d954033388n/aHeodo
2021-01-22GDHA3BRLKQ1QS.docdoc 5b8a09ecc983f2bfa3c172b58755d141faaaa80c8016de77c9cbcdd83805d5abVirustotal results 32.26%Heodo
2021-01-22TQBQVTALTW99VQBX.docdoc fa1737d67834c7d10ef916c5a121bd48f8e7f0164065a6124aa0d0ab5e046cb5n/aHeodo
2021-01-22AJXMVTU.docdoc 18eeb3c4acd968e5fb4a847ef4eb4953690be2b5a9ad36d6f82a9cbc7caa7a53Virustotal results 32.26%Heodo
2021-01-22JGEO2QS.docdoc c7f261f11d0e317860ef68857f8457e85439e702a7c90170b9b74b1508656b99Virustotal results 33.33%Heodo
2021-01-22H8G4IE6Q.docdoc 18a322bc3bc173a8128d00e372d608c3251f083c2587e69c79ec037933928d39n/aHeodo
2021-01-22GG23GFVHAIJS.docdoc df5ff0dd34808825942b6b896c5129f63bc36f8fbbba7f3ce145cced467c662an/aHeodo
2021-01-22U04K15XESLVC68PS.docdoc 1d2d80a3a1d3ba28ca88d827cc5fb6b166f7d41b3f91065e8448f691275bcd3cVirustotal results 31.75%Heodo
2021-01-22TUF6HV8NL50.docdoc 361afbb90589c1dbaba30c9c8b380772449df5b01544e084fe473b501f583129n/aHeodo
2021-01-22HQ79IGQ1TX38C1K.docdoc e26acfd8ba9ac131426a2d9667e8ad19344e9977a884531fd2a2127615481f99Virustotal results 32.26%Heodo
2021-01-2206IM0XS73W6N.docdoc 908db1a1a1782ad566ed5e71adade16d6f3d976df9e5481a602ddb4d7ad53557Virustotal results 29.03%Heodo
2021-01-22FIVA2RJGNQ.docdoc c56e64333878661b5c0a2ca6fafb49c64b2c59dcbbc71dfb9835e5b22d7a80ffVirustotal results 32.26%Heodo
2021-01-22OK57YHHM4YMHDSNI.docdoc 0dc0f00a3ed385b6bff2f9188766ae977a173405c9bfed86474e9f7fccfde9c1n/aHeodo
2021-01-22GXKEY8W8V2EA.docdoc 9508eee151055a57449b53d6489e0a5241de7ef21bdc4599af547a5f1831b538n/aHeodo
2021-01-22BPSR8BATNAA0C.docdoc 980a3949995d00c52383ec46cfdb15a05a9ad20aea7fc2a11a834a7ceffb5484n/aHeodo
2021-01-22ZKCVF8CU0EB.docdoc fa73aaf86c492584aab024beb61b333cb383c5a742ae789e1c20f40d599a9457n/aHeodo
2021-01-22N5P8JRKUICB.docdoc f7b23a3585cbaee380651fac4f092837b16af530c07e962be54d5a1d005a6300n/aHeodo