URLhaus Database

You are currently viewing the URLhaus database entry for http://cr-easy.com/wp-admin/jiazt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:262515
URL: http://cr-easy.com/wp-admin/jiazt/
URL Status:Offline
Host: cr-easy.com
Date added:2019-12-02 20:03:36 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Abused domain (malware) link
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-02 20:04:11 UTC to abuse{at}alchemy[dot]net,dnsadmin{at}alchemy[dot]net)
Takedown time:2 days, 15 hours, 43 minutes Poor
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-12-04PepghSoUrHa1RNPx.exeexe 38b0e08c5d352391fd98bb4a221b9bd6a333bc62477bd819239e86ed04e4954fVirustotal results 8.57%
2019-12-04FR6q7zOrN6dRdlgJZ9wG.exeexe 45c4fef8a3ebbfb0778c758e700ba75531086234d408c44a4fb35d8711090effVirustotal results 12.50%
2019-12-04vkqeJJAxEZPOfAa9wV5G.exeexe 097b1fc1ac632e45ca10da72255aed749cefb433c1b7b3732c7d6445fb8bbf3dVirustotal results 15.28%
2019-12-0403yZtEiAbUzPGz.exeexe c813b72a31f8296ae626e2279614bf163db546e961770e924693a74044ddf45aVirustotal results 10.14%
2019-12-04os.exeexe ad6b248da1a7f38b2b1e1e641c7e4fc1cd71a7a6f4f89c260c02dc1925107f18n/a
2019-12-04riqj4.exeexe 2c0f40bef9fdc7e37e418000d4a4b11e42dd833445e5c434da49d5163b9b2eb0Virustotal results 14.08%
2019-12-04egVGhdsYK33QMCJ1Zu.exeexe 21b4e99e352f843d45a8630099df920afb9b59a14e4bd845aacc02be3ca9897aVirustotal results 14.29%
2019-12-04ZG.exeexe 2542fe290ef9673c0c89063a9c627e43f4358e86d0c305cf0d11b3cb8fa0f758n/a
2019-12-04XisJ.exeexe 9d1d03a26c0ebe64104d2ea81d2965713e0330a2f7ca8f7ea4fbd4525d20ff8bVirustotal results 8.45%Heodo
2019-12-04Z.exeexe 7edb3e848f98c7f185739a876e2d1c97d15e5c10e65d945727001cfde78c1d29n/aHeodo
2019-12-04jtPECuSukgCtB1a.exeexe 9731b2313067e930aefd52b7402e0b503eba05dc04c6338a51322a4c8ddf1d1fn/aHeodo
2019-12-04lf1.exeexe 997a17601e5d6b079b583d914d93bd0f323bebcffbd1fa0035ba9d16807b44bbn/a
2019-12-04RCJjEnmep2TpgT4J.exeexe c2c6923c01d28ec57f5b9ee1a4ad2d6ade0913ba0d9f9c1cf7f9c67ab14d69f5Virustotal results 23.19%
2019-12-04c7zGk2BnFRfU5.exeexe 0566aefd2468a96e88c09ffd627b8c0ac28dfb63218a816e94ce91e19493860dVirustotal results 21.13%
2019-12-04C9bSy8Hnk.exeexe 5907a55d329198d8c9325ee1dca2919ddae7def940990a3aa9793800a3505048n/a
2019-12-03K4.exeexe 5b12dc8fdab0fae089918d8d26bd089edbc7df136d6345000c6410a16bd86dadn/a
2019-12-03RsCqPdcomhhix9xEni.exeexe 354af00a3d68b57383683ac3d98ad6702a9af4b0378045811ca49284b66c6dc2Virustotal results 11.27%Heodo
2019-12-03GII.exeexe 8b4a605429bdc46eeb6c21cce003d2ef6821ae7bd50e5fc2437445345665e80dn/aHeodo
2019-12-03JDT2O4K3wDdsk.exeexe e36c9fa78de7959dd397478189bfbf811c37e3f01052737653c244355fdd6128Virustotal results 11.27%
2019-12-03oGf2Crx8n.exeexe 7c4874b364c9270395d86e57f6addd6e15e567793ab9494f03e6dc7dd03faae4Virustotal results 11.27%Heodo
2019-12-03ZTd1bNwVGNZUfLoXk3.exeexe 43f0916c002afb763adf2958a94b3d126a485b88673b8cbc93acad0e2dda04c4n/aHeodo
2019-12-03iZbOZVqKYIE.exeexe ccdfac611159524e9515eceede8bef7003284e70596724c31810be68d3a50d8fn/aHeodo
2019-12-038PZOFS2Kt.exeexe 64419d12f5b5228516090696c03e1515e85cf05c2ace40a7753bb11eec42bdf3n/aHeodo
2019-12-03br.exeexe 49949ab316294131a349d319d889d0b9c61cf8fca7c2ff4a4ed8fedaa3901aacVirustotal results 7.25%Heodo
2019-12-03cmTxdEXYaY3B.exeexe 84b9b03cebc58e79d6a6b0fb0c6984c05fc12095194f2c0affa389f45fd1fa3an/aHeodo
2019-12-03hI8l96sw2ayNJ.exeexe 8f031a0957652a364c8d127d6474629acfbd1cfbaa8153d0bd24d3774a028915Virustotal results 8.70%Heodo
2019-12-038I0EeX6chDEevDBO.exeexe e99d250748138eeeba7f8fa9b5047a21cdd953f9290f0db505840302092d3cbbVirustotal results 18.57%Heodo
2019-12-03BJe.exeexe d609c83e0d89a0e24f30e211ef3324a396760d0980c46fc763eeb3dc2707f9a8Virustotal results 14.29%Heodo
2019-12-03FC9.exeexe 84e9d08a7b35114ff3116e3c85c669ab05a9c45b9c57d2a1655056fa7626d31aVirustotal results 11.59%Heodo
2019-12-03P.exeexe 5d789a61d54093241b584b6bf2d71330ea26cc8d3ba242ccd44cb3380eabdd12Virustotal results 7.14%Heodo
2019-12-02Kba8fjt0P.exeexe 8e57c31f84866ef2222b22448511b35f05262603da9e7bd6ae3b1e988dec2c68Virustotal results 8.70%Heodo
2019-12-02FNAVIJw1YJlQXYgu8.exeexe 19bd8bafc8f33ee9dddf88511ea3ec4d79e7edfe08b8b6fee3ec93b812e22583Virustotal results 11.27%Heodo
2019-12-02ziTS.exeexe 9653a4ec394de87d912846252ce8144a50a664aefb8f496477eaeb2a11c9baefVirustotal results 15.71%Heodo
2019-12-02LdpYEmtS9uxowj5BY.exeexe e814ea789f7cf7a3e9dabe40eb0f0e1d09289ca67880f900a41c0ccf0d1ceca4n/aHeodo