URLhaus Database

You are currently viewing the URLhaus database entry for http://heinicke.dk/wp-includes/GiJgZKiUjsi9kS12M1l65z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122758
URL: http://heinicke.dk/wp-includes/GiJgZKiUjsi9kS12M1l65z/
URL Status:Offline
Host: heinicke.dk
Date added:2022-03-30 15:45:05 UTC
Last online:2022-04-03 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 15:46:05 UTC to dk-abuse{at}team[dot]blue)
Takedown time:3 days, 22 hours, 23 minutes Bad (down since 2022-04-03 14:09:23 UTC)
Tags:c8fc17ff030feb3383d8889f69abbb emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01YI-204812055.xlsmxlsm 09efe4c37362ec440375541813440e9b179c3f1c6a371184f554d8b8e1e8b6c9Virustotal results 48.39% Heodo
2022-04-01WEK-80206805897.xlsmxlsm 1cef59b0cfd651edd1b587c50988c75a14b39c325a3f41839e3ce51c08f7f753Virustotal results 42.86% Heodo
2022-04-01BB-71391275.xlsmxlsm 303c09084f427ef59bc3be795f3eca2fdbe4a953816cee78c711da6d57a944b6n/a Heodo
2022-04-01JKG-0121052.xlsmxlsm 2efeae28ad35e91b7abb28eec555e20e394693d8454514a43fc119fde473348eVirustotal results 42.86% Heodo
2022-04-01IFZ-9579424388.xlsmxlsm e503bdfaa287dcd3634ddd3c3b00f7c0a162768c200e6739e356328e6c8c1ed1n/a Heodo
2022-04-01DGA-6996800307.xlsmxlsm a657d3b4f65b1da6a9b498efd74772a6b8c393555587694e5da423b8e108ae2eVirustotal results 46.77% Heodo
2022-04-01OX-8294250.xlsmxlsm aa3fff2c2d0daf56b10654b5f1f501b45c0cfd50fef9004498bca2a83c359e69Virustotal results 43.55% Heodo
2022-04-01TW-878991595800130.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01YC-181786573335735.xlsmxlsm e487c02def7287335acf2278332f27a4a585960d8ba68a14c0b8370535440c3cVirustotal results 43.55% Heodo
2022-04-01WXB-2256748889015.xlsmxlsm 8c3a1df0298f1bddbc6946c5ab191ef80476cf4a3a8cefe7493c189035d2f0cbn/a Heodo
2022-04-01EN-9178870.xlsmxlsm 6463322a887744e8e04715bf20b67bc671561c87d8cf5ef5d4791ddfb5f1eb0an/a Heodo
2022-04-01DT-52908268.xlsmxlsm c58a2c92c9c20ae6db820f2aae7783ba62df1a2a08210f6640a310f4a5c0f765Virustotal results 42.62% Heodo
2022-04-01LEU-6512663358.xlsmxlsm e407f7217907368560ef28caf164f34190a5295c4c75afaaeea21386e8bed99cn/a Heodo
2022-04-01KI-88262091516.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 48.39% Heodo
2022-04-01FYA-926963375.xlsmxlsm 4967f52b4eec67dedea5ef764a47c545db43f04f5b0f1355dfa16c8b8bc6e1e8Virustotal results 41.27% Heodo
2022-04-01JLI-8034291808.xlsmxlsm 5c887aec3ff6d6b86adb64e688521d4b396689f6e29bb2106125af1b20b9d5c3Virustotal results 38.10% c8fc17ff030feb3383d8889f69abbb
2022-04-01HK-5804724357483.xlsmxlsm b7a2ba71c06e47b7011fb3b7f3a263a34c991d3eead33a69dbcf967bdeda5a96n/a Heodo
2022-04-01AFC-9412973359.xlsmxlsm 57a73cab7fb65bf97b094b8ea188937cff862e7e55cb179ad32cc6d9200d8855Virustotal results 36.51% Heodo
2022-04-01IA-36318207018899.xlsmxlsm 7fb7f42e37addbbb2765549460c94f9747dba7a15365f6621d0e9fb2d80ae701n/a Heodo
2022-04-01AJ-4864779753487.xlsmxlsm 47b6e78d6a7d4cd13da293ca1246d01543b0da63ccfd3e20830723be355497edn/a Heodo
2022-03-31HLN-03286846.xlsmxlsm 1f89665519be0af8fa6ccf11e12d78adc54cf5560f8826352dd036d8663a9bdbn/a Heodo
2022-03-31RQZ-512384094130649.xlsmxlsm f18597d133d32b346f94d05eb9a0865b4ed9a863e7dbcd4cbf10bb847803c37cn/a Heodo
2022-03-31BF-80969273.xlsmxlsm b240ff1edec81e1d31562cbd34499c1f2085346a7de34e51016cb82e3cb85716n/a Heodo
2022-03-31OP-31361143412742.xlsmxlsm 73a1d60faa31200f09f2567671137d6b5f9be02a97eec33fc20971d151d5c8f1n/a Heodo
2022-03-30n/ahtml c8587a9efbf1951f6c406fc40df0fd513388374a87ab6211d966e193e97ba64an/a