URLhaus Database

You are currently viewing the URLhaus database entry for http://elgrande.com.hk/xxx_zip/verif.myacc.send.net/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:171538
URL: http://elgrande.com.hk/xxx_zip/verif.myacc.send.net/
URL Status:Offline
Host: elgrande.com.hk
Date added:2019-04-05 02:19:19 UTC
Last online:2019-04-15 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-05 02:20:08 UTC to abuse{at}wtthk[dot]com[dot]hk)
Takedown time:10 days, 9 hours, 16 minutes Bad (down since 2019-04-15 11:36:28 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-062019_04___BIZ_22212820373586446___352961803679224.docdoc 8a35d2c20608112363a128390050dcae45106babe7b552fc7672c29f8b284375n/a Heodo
2019-04-062019_04___DOCS_8527238139795___4412081073270.docdoc b3ff81bf64f077e1b466d3696c3528f9c644d503b515473b16803610f240dd05Virustotal results 44.07% 
2019-04-062019_04___PAY_869855050050___59485596169889934.docdoc 57d1d4fbdc8ad71fd6dc609256ba9ffd05cd85ffe45a60a12615568ed08a655fn/a Heodo
2019-04-062019_04___REC_5874734062844647311___05587902084.docdoc 2ea0e26084bc2c5abcdc83efc8dd5f1071f44e7975c79e125cd441b314bfdac5n/a Heodo
2019-04-062019_04___ACC_8640851469721___50744793633.docdoc 9950356d667ededba4bccfb27bdd6130cc341804ddf35f3a28dc060d29be86e2n/a Heodo
2019-04-062019_04___INSTR_35796990577___9456677312690107.docdoc eba143b8f9ea163949037b683622c1cf9672e9a4e63513ecd20ebe1aff4e3ff5Virustotal results 36.84% Heodo
2019-04-062019_04___ACC_156463081___11172405717946.docdoc 9cded79cf1bb9165b4d0f8b996706f745cba51a96191354eedc255ba6265857fn/a Heodo
2019-04-062019_04___RECH_0431650243___59078914479622262753.docdoc b171eceb553936eb770763dfd6115fc6f78ca8d88bc6aa2b3f660f9c5c17b286n/a Heodo
2019-04-062019_04___INSTR_03635367425___495610431836699.docdoc f4282b6fc250485ebd045d3008195a5c3e2b385c5caaada93ea221f53326d3ecn/a Heodo
2019-04-062019_04___ACC_657869332293___79954813323887532.docdoc 0ad46f34200d42b625843e3e3f1b3e0d8547006862977766858d55fde59bb61fVirustotal results 28.33% Heodo
2019-04-062019_04___DOCS_5424529347439271363___0432303796962105.docdoc 51f2b641b6cf6bfa3cd6b58809672cb4168eebf6ed0aebe9e96be5f98f3f9e02n/a Heodo
2019-04-062019_04___INSTR_10890318156920___21426861334.docdoc 95849588def5977986569c59b046be25deef8c7612804726ac96e53c0f1d2a8fn/a Heodo
2019-04-062019_04___PAY_049320841131___1748031881.docdoc e39863e66ab0f1bf0b8d35f2715d3de220f6bb3d0c28b68d8f14d53ed1acb7e4Virustotal results 31.03% Heodo
2019-04-062019_04___REC_44442659781___554869767028.docdoc 48b35306314350b996c26ab3ef587663b6a008cf550a213773445a47a6d58acbn/a Heodo
2019-04-062019_04___QE3034082416052807___9758634233821775.docdoc ba78bac81758981def2ca13c6678d5163b3c4d9f7891555e777a3f1893eb8ac6n/a Heodo
2019-04-062019_04___DOCS_7400297966___9977660147296039556.docdoc f18c7ff29f31a1495f12fb6775bf1cd1ccb6eda9658888ed85ab69cf00058f99n/a Heodo
2019-04-062019_04___INSTR_44040979684___196556257231871.docdoc 80f8da502cd709185e2cbadca13de5fb1c1663ea5cd99f2ba9a351245ddee784Virustotal results 28.33% Heodo
2019-04-062019_04___RECH_396272401___5967707271082.docdoc bd1ef49f771480b20bc5aa80d46132cdb182a5bcf7576d97f957b77850935e3cVirustotal results 28.07% Heodo
2019-04-062019_04___CNQVT8324687302068504579___838731552688495943.docdoc d1d756451258f60d10e1c46540438f9a7c9ad84bfe7b4a1cb944ae02e456d3aaVirustotal results 28.33% Heodo
2019-04-052019_04___RECH_44518758454493___6389136920811697.docdoc e9a0aabcf4e854ca4b16e9ebd2d228b2e581abc12d27ef34b9f8a5978d224128Virustotal results 28.07% Heodo
2019-04-052019_04___DOCS_51090472418550___4133929962117.docdoc 6daf0a0a5112444b7ffa2012fd62794d1658e21a79018fc3a69d48d6c99d4a8aVirustotal results 29.82% Heodo
2019-04-052019_04___AJUH5409886332554747___8185162493.docdoc d72aab1ec1befb352a29892128bd8aba31531e6d965f903973fbb15bd2f71584Virustotal results 27.59% Heodo
2019-04-052019_04___ACC_247236796439135___271473951189.docdoc 310c672343531ecc8fb2bc22b979a34f6e3c3d6c56eaad0dadeecade3e6c64d9n/a Heodo
2019-04-052019_04___DOCS_981671006597155903___0359393520069754330.docdoc aa4dbc44304abe8aa207e31f7f0eaabad3933dccd1c3d004ab68edc87e75cee5Virustotal results 29.09% 
2019-04-052019_04___DOCS_078634334___92204061309.docdoc 60973bfc7ccac458d9ac4b7192a40774316b04d86cdb106b0c205d75778b7c65n/a Heodo
2019-04-052019_04___DOCS_519158778005___0329165907.docdoc e8ca6c66c79cca9404a9f6a6920ff02010dc799435381a97fd5c57cf0c3abb41Virustotal results 28.81%Heodo
2019-04-052019_04___BIZ_00603247516904___89710287677778081.docdoc 3a119906f5ccc2ff4f39245ba6d788209a21ae74131854b3347facc6854308c2Virustotal results 27.87% Heodo
2019-04-052019_04___RECH_30039904173671442810___8838042670532.docdoc 39fd7a9a543a395a5c04e69d739075e8c684b697e9f7161e9cfdf81ebb162340Virustotal results 28.33% Heodo
2019-04-052019_04___ACC_36743501377806289639___87779861028278.docdoc 23d3fe9d332bb9159964b608c1099f18f980c434b600c9fe82c53b9db30a80a2n/a Heodo
2019-04-052019_04___INSTR_429900169___902033705125243.docdoc 3cbf2d0b6a25ebefb9e39053c09ea1ada864ad2d2e2e6b20f97054ba14b35171Virustotal results 28.33% Heodo
2019-04-052019_04___REC_2648888377___715097894930224.docdoc 07be913ac6e2caf9d7104debcda9d259a8109f7f45693f51e7a8125cb8b87cb2Virustotal results 29.82% Heodo
2019-04-052019_04___INSTR_2207303559___720210978633700.docdoc 83311ed9909cc46c0b2ef39058079c5eb695bf5097a2c558b021846c026cb1c4Virustotal results 30.36% Heodo
2019-04-052019_04___BIZ_555523004560___6997052107352729.docdoc 17dad3ebd5a305c0a8b9218d3bf755d6f335ee4e3f4f9eb28c791d8cc031f910Virustotal results 27.87% Heodo
2019-04-052019_04___PAY_94704764758398073___08491894653.docdoc a815f881314204ccc95a61305add749fc5bfcab40834f81c1dde379c1a925459Virustotal results 28.81% Heodo
2019-04-052019_04___JXHN8128521908___066351704.docdoc 8cc7738a7e40e5fbf76ab3b9815864e9cc948aa7ad1fadc750877e40aba3a564Virustotal results 29.31% Heodo
2019-04-052019_04___VS59254387856837396466___059612571.docdoc 72f7d221856efa7923e2d504f4964be87b37c8717712d7a4bdcc4e5c1569b554Virustotal results 28.81% Heodo
2019-04-052019_04___T42527157031366971___3375660450815630193.docdoc c6a61e437e4b6f487932736f0c5a8e7c78b146662073f7f66c07791c45e81eaaVirustotal results 28.81% Heodo
2019-04-052019_04___RECH_27902329396___47818307345051499054.docdoc 81dcaed35cdb31c0a5e1d807b32d801d7b7dc91dd6864a0e52d9ad5245663430Virustotal results 27.59% Heodo
2019-04-052019_04___RECH_12718795308774272951___98062156351936876335.docdoc b4b12e8646c35ae03b3ae6a4ba14f8cc9210a8770548d0198d82bbc0a647c1dbVirustotal results 28.33% Heodo
2019-04-052019_04___INSTR_35768199250679___13897579277.docdoc 320968b90f57722f2e5bb07c6d015507b66f8c7885e01d9c7cdddeea3b567502n/a Heodo
2019-04-052019_04___RECH_119511255392646638___93198587960903.docdoc 9f1f0f2d2ce1829eefc8cb32e65c611afe318002fd3e4bff5c00c7d2b8c17e91n/a Heodo
2019-04-052019_04___PAY_600691335253950___24467367419287.docdoc 19aa6770f06b8c815f90385b16e7d137cd62c95251d1106f5a69b28f1cf5d1b1n/a Heodo
2019-04-052019_04___PAY_35945258372501___24215184421.docdoc 1818d4e4da77657198addcd911e13e120adfc0d712dc55d1f4d36d750fed27c9Virustotal results 24.59% Heodo
2019-04-052019_04___REC_36284426335214895595___573024646276.docdoc c5f0dbe9e0d454c80ce48831af0d621205902a3a62f33d78b5e1d768c181cb55Virustotal results 27.12% 
2019-04-052019_04___BIZ_14844360993222___19223779274197.docdoc d86a1b66c56cef437433626f18a68d23869b9b65ecc769040d9bfb2781a30d5aVirustotal results 25.42% Heodo
2019-04-052019_04___INSTR_19174922459570693___22334165845.docdoc f6ae768a9a919180418643f94decb565accd3e66b240b5b791905393635e1257Virustotal results 27.59% Heodo
2019-04-052019_04___DOCS_640703709561625377___881779226326.docdoc 52a0d8a8e2f62c2a799654c682e309a58c56a13eb1b2cf24b3d19bb7dbfecf8dVirustotal results 26.67% Heodo
2019-04-052019_04___REC_387167704399266978___96409786228745.docdoc cd099558a6002c4011414a907b76510ab5fe7b20a3ffafe6129cd153ea7b5542n/a Heodo
2019-04-052019_04___BIZ_52113439442882818761___33959820508.docdoc 80fdb85fbcc0c156c97f0b04ea5c25e22d17ff8aea452f14f1384c28df202dc3Virustotal results 27.12% Heodo
2019-04-052019_04___RECH_897913112664390___066746235392616675.docdoc 3306210658988d83672d5d78e384a604ac1063ac40d4818678f3868d0fb7e243Virustotal results 26.67% Heodo
2019-04-052019_04___INSTR_46162305253939363___3645364657.docdoc dda9dc159876d3ee1d46041fd8ee1582a650d3ff723180b8d5381d830a589cd5Virustotal results 26.32% Heodo
2019-04-052019_04___BIZ_6913716739068798761___52758116851821430.docdoc b66e8427fdb72abea4cd4ac9ab9d3cf814970e15c721e32b73c5998c8c352153Virustotal results 37.74% Heodo
2019-04-052019_04___BIZ_9956336061___84143908947881.docdoc e4410d509dc8f2c5e77a52c6a70b1bcab8407c3875f92b2ba63088c1d71b70d5Virustotal results 37.10% Heodo
2019-04-052019_04___RECH_56925390863790216___5793222914011.docdoc d4fead67c10dee90c6c469d07f875d4d8dbb8e8f90ddb5ec9262a2dca9ec7df6n/a Heodo
2019-04-052019_04___ACC_29121715444454723654___7654397065.docdoc 4daf94d52448f6f8750f7c5f6c853546fcbc947a320ce844c8cc5395b0a6835dVirustotal results 31.67% Heodo
2019-04-052019_04___WGE005638728573406113___84424580463.docdoc 2686901e81c268f00d8212d1d2dfcdaf9f4761767056c243e1dd525ae427eceeVirustotal results 35.71% Heodo
2019-04-052019_04___BIZ_1435176555081213___806672072021944.docdoc 12aceb6275694181738acfe2044c38996c149474b04a32a3f847d3ad4042e635Virustotal results 40.35% Heodo
2019-04-052019_04___UTIJ2928661955058575___7232211954743521.docdoc 172d8215589e5d609adbe463c149f938c493cac93b5824a5e5d681dc36a627d5Virustotal results 33.33% Heodo