URLhaus Database

You are currently viewing the URLhaus database entry for http://grasscutter.sakuraweb.com/wp-admin/Document/ZsUUTzYbqan3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:185017
URL: http://grasscutter.sakuraweb.com/wp-admin/Document/ZsUUTzYbqan3/
URL Status:Offline
Host: grasscutter.sakuraweb.com
Date added:2019-04-25 23:07:05 UTC
Last online:2019-04-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-25 23:08:02 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:3 days, 9 hours, 3 minutes Bad (down since 2019-04-29 08:11:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-27INC_20472850761US_Apr_28_2019.zipzip 0eeb09b6a6cfd541bd1963b4450ca66f65117d6259e9336bc65b318784e00071n/a 
2019-04-27Document_1231350177US_Apr_28_2019.zipzip d22003c45ed570b941a88ae91f326e8513ba0e718b34a4f80e9bbb3bc144b6d1n/a 
2019-04-27FILE_14375579871US_Apr_28_2019.zipzip cc8bd184f04c106924d6670645755bc3d8ef510d6f7c512edc9dca982a77d410n/a 
2019-04-27INC_6715349127US_Apr_27_2019.zipzip 74c8ed07e780852278c4ac4d202aa0e8a237711747f242987a1a8659c3b1d167n/a 
2019-04-27Document_7734827139US_Apr_27_2019.zipzip 64ed0166089e24f350f1b388cf69681405b8436d1dbca7176177bb11fea72aa1n/a 
2019-04-27Document_6096760869US_Apr_27_2019.zipzip 9bc4cd378550a0ed2553c8b7773fa4f35f9015ed4d5cddbb47dd78989d598bb8n/a 
2019-04-27SCAN_24986310722US_Apr_27_2019.zipzip 5537ef56233523514a2add98a067f52a883f1dd60fadec822fe7374bd9c89db3n/a 
2019-04-27FILE_0841428905US_Apr_27_2019.zipzip 05de360ce29128f91211c9c247675b202c79c219a1fe20a5af8cd9d4e49d37b2n/a 
2019-04-27INC_0266481961US_Apr_27_2019.zipzip 4d744c703064855498126808af494ac4e9f0c1b3e3c51244d2029e1540e63e06n/a 
2019-04-27FILE_661638524126US_Apr_27_2019.zipzip bf6179cdf4f9b9b5c15d878274ab15a10a4cba2f4b12e6193cc31ddd6bdcc00dn/a 
2019-04-27LLC_33454494932US_Apr_27_2019.zipzip 6d9b2bdab8fd9becfc1c14a77ebcfa6b5bb18b4942e26c8b4e7f171e1646e9fan/a 
2019-04-27Document_566786418220US_Apr_27_2019.zipzip f62dff9947052af141ad0b1f2aa40568aed67f603a530bcd2a24d6407f24a0d4n/a 
2019-04-27LLC_5749464045US_Apr_27_2019.zipzip 8742173a2544ce8f7a97c776842f9828d2579fb075a7f1ca5a74c47c8daf021an/a 
2019-04-27Document_96053736443US_Apr_27_2019.zipzip d2b75f494dac79923e0aef05da6ddb3c21e72169f7b0b2e9039d65194756aed2n/a 
2019-04-27FILE_744078712359US_Apr_27_2019.zipzip 3fd83bf835cacfd066490ffb1fc73554457bc18ecd7e96cd28b7a491eb9f7c89n/a 
2019-04-27SCAN_7595658611US_Apr_27_2019.zipzip fad785afd4e36bbe46f1635aa3dbd0364b85b85ccfe6d41ff78ed6471a5d5e14n/a 
2019-04-27LLC_733981561950US_Apr_27_2019.zipzip 238e9169388b150aa9100f4dc76482fcc6d72adddee9a44c557b5e52b3761f6cn/a 
2019-04-27DOC_918977447008US_Apr_27_2019.zipzip c64aa19fa83b0fa152307d0748a1645557f45bfb7a2c940da301022de680f05an/a 
2019-04-27DOC_389980731521US_Apr_27_2019.zipzip e15d77bdb517c8e74ce54106d8bc5010de34d117d31d7f98496b3d2cf53dfa52n/a 
2019-04-27INC_2447667699US_Apr_27_2019.zipzip 65bfde6d77167c19cdc31195bf378ae2cdff260388ce8445212dfd91335eed2fn/a 
2019-04-27DOC_6489370265US_Apr_27_2019.zipzip 2601b51d9dcd5c91787b914d4692249b589158ad4a8cb646ed88bc7609b849ean/a 
2019-04-27FILE_277864612084US_Apr_27_2019.zipzip d2e068be918f3d44074589dedcba8e9d05f0453bf1c93d0163677424ef184f92n/a 
2019-04-27INC_83120057924US_Apr_27_2019.zipzip 72ade2fea7a08f8f47324137fd86c327677e795ed497b065692bda7987366b9fn/a 
2019-04-27INC_744771328993US_Apr_27_2019.zipzip 0225dc4a68807952cd3569f91e2428997f11801d25d6cfa6e1f1afe4c3071017n/a 
2019-04-27LLC_7525218281US_Apr_27_2019.zipzip 6bb1352e2b2a1b2a80fd2744994cfac5ac42f346de3e29f4cac933e9ea21355cn/a 
2019-04-27SCAN_39336205308US_Apr_27_2019.zipzip 3258cb5df6794a522c2a73ac1c5281caf6ca011320782121782176f5125c4fd9n/a 
2019-04-27DOC_77620027552US_Apr_27_2019.zipzip 30a0b9dd4b9ef6f401fc8cf265864545fcbf84387e5e90c11d5bacf67ef8ffd3n/a 
2019-04-27Document_855328533962US_Apr_27_2019.zipzip 4e96b4fc1fb0dbbda99e2d69344170d9882bfbf2766b2005d0b1f42c671ca612n/a 
2019-04-27INC_870029297301US_Apr_27_2019.zipzip 6f8dbf033b55d6b5730f40d6875347540bd8ab66f206268a3c457931b99e56een/a 
2019-04-27DOC_30533638356US_Apr_27_2019.zipzip e084a7dd7f02020ed129d8d2069ea6cf003e9ec81db8c73853d69e31ad529c42n/a 
2019-04-27LLC_203585508003US_Apr_27_2019.zipzip 8e748af44b8c8a64cf38575989d5993c15284f3e6c866ea5bea10a74b00f2c03n/a 
2019-04-27DOC_3598164503US_Apr_27_2019.zipzip 0380302a70b32251dbfb60fcdb831e2eb582982588ad9ad09d9638eae6543493n/a 
2019-04-27Document_131332905626US_Apr_27_2019.zipzip de45d12356bf82b9dd10a46c954bf5fed49136e50c591a4e0d2dd5832bab5627n/a 
2019-04-27Document_53809985173US_Apr_27_2019.zipzip e3c263788db71b359f40fae2b1442237806bce1667d569bce69229fc014d84edn/a 
2019-04-27FILE_7673499350US_Apr_27_2019.zipzip 73ce9e2fa10a11b30dca11891f49f708743140382d9783cee981d5b84d3e98bbn/a 
2019-04-27SCAN_88037235196US_Apr_27_2019.zipzip 7775053f0aa2c23b39608baa7d1e7c51d944f8ab73eae517a79dc9d2b119fbdbn/a 
2019-04-26INC_9464266035US_Apr_27_2019.zipzip 14eb51b9f66ffee211db7433147c6db8c6642e92b064747ff1e93f3e7714e793n/a 
2019-04-26INC_55786118589US_Apr_27_2019.zipzip 41bcc992f463b1231596a6827a70a816b6c556963c65b8da8b80e55146d645cen/a 
2019-04-26SCAN_267920955208US_Apr_27_2019.zipzip 93cdeb32b1b675b50c3e86d77c4bece77e40275f763c758f0bee36b81e2b9f6cn/a 
2019-04-26SCAN_354737586988US_Apr_27_2019.zipzip aff9cf039cba48c38aa072a4951df0edef888870fe023eace9abad52fb877ee9n/a 
2019-04-26SCAN_84623932914US_Apr_26_2019.zipzip 86821e26b09bd9d5ca518c5d2a915d14fdac6558d29aa88c8542aa4d575897b4n/a 
2019-04-26SCAN_9946938342US_Apr_26_2019.docdoc fcc56f6e583e33f8314001d67db823ecb4f6f98434ed54174aa4af4c507bd4bcVirustotal results 29.51% Heodo
2019-04-26DOC_43947383052US_Apr_26_2019.docdoc 9e4d1bbb525d72b75d70a3043e293e7105fdce7fc1c7fdd2a0a112c5b7d40548n/a 
2019-04-26DOC_585282804759US_Apr_26_2019.docdoc 1f36292a0e7afdabbe9490a5ce10e366a117dae1183e7ae81b87adb87634a79aVirustotal results 28.81% Heodo
2019-04-26SCAN_9032366093US_Apr_26_2019.docdoc 87da291e7d68639a86c806608189d6c26b20d01808956bbb5c22b540c4ffc79bVirustotal results 29.51% Heodo
2019-04-26INC_2898574769US_Apr_26_2019.docdoc 5bbf064dfa6404a2f999ec81f6dffde3b9276da7cc1cd530bfa15ae71b1efebaVirustotal results 31.15% Heodo
2019-04-26FILE_6355916594US_Apr_26_2019.docdoc 28b73ffab30e520bf8cee7181ed94476c94c2648431f771aae0403242a3092b1Virustotal results 27.59% Heodo
2019-04-26DOC_1651794707US_Apr_26_2019.docdoc 2d8657ddef24bf6a614be6b191d81d604035ef998633bb52ca99eeb390630d81Virustotal results 29.51% Heodo
2019-04-26LLC_38601256810US_Apr_26_2019.docdoc a6afe1b349587b22463f2ce9bea4383a631d3a2aa8041b7820f927bf2f6b6237Virustotal results 29.51% Heodo
2019-04-26Document_17194189970US_Apr_26_2019.docdoc a050166f242d26cc107033f485b1618ba61d4749a46f91458f93570dc93b45a4Virustotal results 29.51% Heodo
2019-04-26FILE_12044196812US_Apr_26_2019.docdoc 796993d4f3251d60c9b534c46b937021e646bac58e42ce21fddb008acc3a73f0Virustotal results 29.03% Heodo
2019-04-26DOC_660124093245US_Apr_26_2019.docdoc 77ccc470c377e4a22e0091d0abd3f91cec17b6e06c0e17d8f87dbbbd735bfe0bVirustotal results 32.79% Heodo
2019-04-26DOC_2912997914US_Apr_26_2019.docdoc 9fe28f27c0db9df3580f65069affb7f47171d910f69035ffdeeac5a545ab4ec9n/a Heodo
2019-04-26Document_217353002774US_Apr_26_2019.docdoc 5a33cba1e854fb298486fe6ba6ebb071e045cb698aec109561178b2a66567662n/a Heodo
2019-04-26INC_42002013874US_Apr_26_2019.docdoc 3889458cad2eccfcd7f8ec5c842dd30edec24f36a37abde0e9359dd7117524e7Virustotal results 33.33% Heodo
2019-04-26FILE_0753006443US_Apr_26_2019.docdoc 6012a514bfe3d7f535fcfc63a8810d2599bc7cf0a64a22f0f03a5f78c27ba183Virustotal results 31.15% Heodo
2019-04-26DOC_958022300438US_Apr_26_2019.docdoc 407f21c8583dbf70a0069162b9f7c0ec142b63e05d4d94ec8e4c85345bf759d9Virustotal results 31.67% Heodo
2019-04-26INC_03641228493US_Apr_26_2019.docdoc 8052cbfa6f3348c2cbdcaf35a02d470947238347278421560a93400473a5e75aVirustotal results 31.15% Heodo
2019-04-26DOC_93825312913US_Apr_26_2019.docdoc 751ccbeabee910ea022ebc97fde11d5e1c3bba9f83b6d2df09a927924eb1e60eVirustotal results 32.20% Heodo
2019-04-26LLC_7623755876US_Apr_26_2019.docdoc fd84376ecb2845381d03f46851fb6328f5c0f26c51fb515c74f21b2326031630n/a Heodo
2019-04-26DOC_510729821225US_Apr_26_2019.docdoc d673444e2d8e9d1d919b1cefdeeb0dc783106192d1fd1fecb401df43134449e9n/a Heodo
2019-04-26SCAN_3357433944US_Apr_26_2019.docdoc c22381c768d93356bda637be73a296a73f5b51756cff0c9d0eee0661e2e967a9n/a Heodo
2019-04-26INC_081310577075US_Apr_26_2019.docdoc 8065d2137332893c6e189b09a0e6b480e2f2955e827e0b67e4418e6a268da467Virustotal results 32.26% Heodo
2019-04-26LLC_95970580728US_Apr_26_2019.docdoc 7a6a2c210aefa9f680207555c2b909616b54e3999945d22a47241c2987debd7bn/a Heodo
2019-04-26FILE_85115644932US_Apr_26_2019.docdoc 3dbb4ca641797b6f3729fbd6512e83b47426b4a20d6b490d81100dcd6786d15eVirustotal results 32.79% Heodo
2019-04-26LLC_896196459489US_Apr_26_2019.docdoc 85986ff033d06fc7f8b1eaff949a4ad970240c2a64bada0f041756bcbf184bb4Virustotal results 35.59% 
2019-04-25DOC_41959075987US_Apr_26_2019.docdoc 828b7e9914f932108e52249577fa80987f20ebda94b8654fdc2964baa4d929a4Virustotal results 33.90% Heodo
2019-04-25SCAN_5493369351US_Apr_26_2019.docdoc 26ca73ee3cbc5062f47556b88c88609a17dda511375f29fe7271300cb82da360Virustotal results 31.67% Heodo