URLhaus Database

You are currently viewing the URLhaus database entry for http://elgrande.com.hk/OLD/uJ1810/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272226
URL: http://elgrande.com.hk/OLD/uJ1810/
URL Status:Offline
Host: elgrande.com.hk
Date added:2019-12-19 01:23:04 UTC
Last online:2019-12-20 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-19 01:24:03 UTC to abuse-wtt{at}hkbn[dot]com[dot]hk)
Takedown time:1 day, 1 hours, 38 minutes Poor (down since 2019-12-20 03:02:04 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20Bonus Payment Notification 737603311.docdoc e8f4adbc33575dfdc6cc8046ec0478baee34237bda285c3e9fd4798aea4ea516Virustotal results 37.10% 
2019-12-19Bonus Payment Notification gz965499395.docdoc 8d3e771513bc024e170ab926ed232211058a7255362ea6e7ffa389dae92b7fe6Virustotal results 36.67% Heodo
2019-12-19Notify AT352563235.docdoc f94d841b4359be57b37745252d21aef9a4a511bfe3b52998753b001d38415849Virustotal results 29.51% 
2019-12-19Bonus Payment Notification t66913.docdoc f6c6fcf32c8bd79f202d6a37053cfc2268797fac3052aeb52bd01c7869bcd0a6Virustotal results 27.42% Heodo
2019-12-19Pay Payment B44924.docdoc c81fa6a0d384474c75454f40007dee1c7c00275f1e049246ba3025a46be69bcaVirustotal results 29.03% Heodo
2019-12-19Bonus Payment Notification PJX44294519.docdoc 60d9761ec33a814667a8a09a86ce91f7b3bef4d2591e58b59b5a8a5fd475aeecVirustotal results 30.65% Heodo
2019-12-19Bonus Payment l419278081.docdoc 8eabac636c65cf97f66d75b737a3563e8a80fffce129742ecd595a1b5b07fb12Virustotal results 31.15% Heodo
2019-12-19Bonus Payment Notification OY35219534.docdoc 52e516af633262f966dd22ac5895849890c9020f5a2e387646fa25449e437fb4Virustotal results 25.81% Heodo
2019-12-19Pay t49.docdoc 37a893b98d380296db389c96da55abb6cf62f275bf0343f24bad9ac1e702a39aVirustotal results 22.95% 
2019-12-19Bonus Tl0828136.docdoc 50502b1309e5510dc666c2dd81f978bacd097de74ad3839f00cf37bd162c193aVirustotal results 27.42% Heodo
2019-12-19Bonus Payment Notification gE798.docdoc ea6a07b1b29eadac9b4ca88df36099ac5145e05cebd6b2b05ecf590dbca280c8n/a Heodo
2019-12-19Pay Payment T34.docdoc 2b13889d5f4a071ba4f42e8afe9b791682ccda5750819138b8968b4416343fd2n/a 
2019-12-19Bonus Payment fYWv321372296.docdoc 1d9a2835541ba7470575df473b1d5a565ec98f7204173e5d2da011ca69e51e35n/a Heodo
2019-12-19Bonus Payment Notification 57756.docdoc d682c920cb5701d126dc0ef943e21d7a5c2daa7b5e07c7faabf47ca7bfe7bd51n/a Heodo
2019-12-19Bonus Payment Notification mXVj87022831.docdoc b10a94e113bb1f430e437f788a82ef32bbfa9f18f82a7dbe09f633298bfc7babVirustotal results 20.97% Heodo
2019-12-19Bonus Payment Notification I25858.docdoc ca7caed0efe4b99e0cbb87397f8766bcb969c59f646e5afacc122d32378725fdVirustotal results 27.87% Heodo
2019-12-19Notify h047.docdoc 826145f8cd7d41889db4b1423dabac9725d7b7f665aac33dce2b1252cf1e6b43Virustotal results 27.42% 
2019-12-19Bonus Payment dImq427301734.docdoc 7ef6c8bba32a08498fa348b97b54ff39ec51d262b9c14176c81d0c4ce5a43150Virustotal results 27.27% Heodo
2019-12-19Bonus Payment Notification AbdN351445.docdoc 320e90e290901f78c4b9e8ea11988debf3c58e18cb1b0ac0a09873a9302d450en/a Heodo
2019-12-19Bonus Payment Notification Bf531847645.docdoc bf2c599c55cd3fc52d6894c58c06343c0295dbf14608695b148b2cd386d4c87eVirustotal results 26.23%