URLhaus Database

You are currently viewing the URLhaus database entry for http://elgrande.com.hk/xxx_zip/va9tn-nlx1m-oodn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:174002
URL: http://elgrande.com.hk/xxx_zip/va9tn-nlx1m-oodn/
URL Status:Offline
Host: elgrande.com.hk
Date added:2019-04-09 14:46:07 UTC
Last online:2019-04-15 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-09 14:48:02 UTC to abuse{at}wtthk[dot]com[dot]hk)
Takedown time:5 days, 20 hours, 48 minutes Bad (down since 2019-04-15 11:36:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-124998974932_April_11_2019.docdoc 4ea86fe9517aa55e4198322fb6eadd5e398ef53adc291d1c790d858b8dea5ecaVirustotal results 51.72% Heodo
2019-04-1043298063348_April_10_2019.jsjs 26b5d6c8934dbf593f2cc541bacac6e7812d71ddec256eb7bb4e9dd61b9c13b4n/aHeodo
2019-04-104499677899_April_10_2019.jsjs 7853439472ed9cd4358d92492c3abbb44d2ae46a2e3fbceebea2bcd858e4ebaaVirustotal results 8.93% Heodo
2019-04-102016351628_April_10_2019.jsjs fded1345d0108bf6da569dbb8b00e143b393e89c87cb201965cd1da0631ad4a8Virustotal results 5.36% 
2019-04-10958391626295_April_10_2019.jsjs 7ddfffb789cb316a55ff6f7c0dea5a703dbe3cbdd25d70cf6cc60481e90a057cVirustotal results 6.90% Heodo
2019-04-09812494784508_April_10_2019.zipzip c45659b14b282beefdb20df1345125b08bc3f5ec9873729b6262a58dbbbddae1n/a 
2019-04-09403602744970_April_10_2019.zipzip 29845982bd22ce7b031267ed59efdcf10e72387ebd580756d8c8a13bbac33184n/a 
2019-04-0900512093972_April_10_2019.zipzip e7f118820f681371328d1c1f193c822b12fd2dd98bf2bfbd29e3f5996c422fdbn/a 
2019-04-09153441497705_April_10_2019.zipzip 01688575e5c93434e96b691e05e0ea193d97909ac02eb6ab272b51b87199535cn/a 
2019-04-09909899293905_April_10_2019.zipzip cc945023b03984b2ff682e177c8a0479b39a5302a120de5067de0a67a1d7542an/a 
2019-04-0950351825943_April_09_2019.zipzip 376fdf4d7d5c8942e26f05ff76fbd405bc310ab00cbee5317426dad61e8abef3n/a 
2019-04-0904432991961_April_09_2019.zipzip 5cb5b9e3d9411c156f6a8ea323fbc8b5dff4fa46d9bac4012360db75a3f26d08n/a 
2019-04-0954577050808_April_09_2019.zipzip ff0dd7e8f08b94f32ddbcf5c7de7efe1a539cd359c153ab1786abafe6150ba26n/a 
2019-04-0972757697004_April_09_2019.zipzip 7df5c2fcae5d629692a1e7c46b0603d9c81eba2d90e597205667cdb63dbcd170n/a 
2019-04-09453027416056_April_09_2019.zipzip ec13cdac3b494b54f838e09b0fba63d934ff553b4e3fa49240df8cfdcb3b2d4an/a 
2019-04-09746375050506_April_09_2019.zipzip ce818871018d43019c40f08604dde7abe6fe1c3a244233be09e91eb099f70c7dn/a 
2019-04-096925393048_April_09_2019.zipzip aa1f9ccb415ec82018fc215376ad43e2680133c7f0d9d515caafdc1cb1e23c8en/a 
2019-04-095233729182_April_09_2019.docdoc 9efb03fce5fa761348c993c5b5fe23d0c9563c5d55e40c323ef05a26e4ea96f8n/a Heodo
2019-04-0944147359524_April_09_2019.docdoc 33613c7623f93844d0792236a7f21f3145434cc8d611a29060b6a9881773cec7n/a Heodo
2019-04-09780278530289_April_09_2019.docdoc 445bb685c5f0766fc0d2cafa048eed71712bf82730320a50cc531161df7a560en/a Heodo
2019-04-099705862244_April_09_2019.docdoc 76be863e92e0774d2a46a90cd1249a22f692797ff83297c78ff70aacd4548abdVirustotal results 22.41% Heodo
2019-04-0909692067745_April_09_2019.docdoc 7d7c938b29923d7d03dc136173b89c706374f1b86488b125449e4e8a8d866871Virustotal results 22.95% Heodo
2019-04-0918485005239_April_09_2019.docdoc 3c1cef7865984c52e42b2562cf0159b3c09bf0a384c7fa08c3ff92862b4da14bVirustotal results 22.95% Heodo
2019-04-09738160472634_April_09_2019.docdoc 71252b9d11d05a1dfac6bf9af6399eff6a850cda4b572ae723ac2497370d4568Virustotal results 23.33% Heodo