URLhaus Database

You are currently viewing the URLhaus database entry for http://heinicke.dk/wp-includes/GiJgZKiUjsi9kS12M1l65z/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2122762
URL: http://heinicke.dk/wp-includes/GiJgZKiUjsi9kS12M1l65z/?i=1
URL Status:Offline
Host: heinicke.dk
Date added:2022-03-30 15:50:04 UTC
Last online:2022-04-03 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 15:51:06 UTC to dk-abuse{at}team[dot]blue)
Takedown time:3 days, 21 hours, 56 minutes Bad (down since 2022-04-03 13:47:19 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01YI-204812055.xlsmxlsm 09efe4c37362ec440375541813440e9b179c3f1c6a371184f554d8b8e1e8b6c9n/a Heodo
2022-04-01WEK-80206805897.xlsmxlsm 1cef59b0cfd651edd1b587c50988c75a14b39c325a3f41839e3ce51c08f7f753Virustotal results 42.86% Heodo
2022-04-01CW-7991447407.xlsmxlsm b9a82fa6fb67d3ca785a7d8d842c76b3beecd65c9789af664049e029ce4e9a7aVirustotal results 45.16% Heodo
2022-04-01JB-992952764.xlsmxlsm f316a9b48040c007a792f5b99f7367b7d6996c7db03a377dd159a22db01e6546n/a Heodo
2022-04-01IUC-856640931.xlsmxlsm 151bebbe36787d4fa1411ea5ea657240e196378969813eb1c1e09d0e4e647ee8n/a Heodo
2022-04-01YGQ-4155923407255.xlsmxlsm b25b9d420c3585bd014abd2e590a74feab98bbb0ee612c465a5e152b28c67e0bn/a Heodo
2022-04-01TW-878991595800130.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01WC-96928732486033.xlsmxlsm e659479a435f37e03d325154ad864519c5a6853aac0f16d605d7560f3a4a0863n/a Heodo
2022-04-01WXB-2256748889015.xlsmxlsm 8c3a1df0298f1bddbc6946c5ab191ef80476cf4a3a8cefe7493c189035d2f0cbn/a Heodo
2022-03-305289916663159217244.xlsxls a1ba5ac09b442e2f6efad0a758c88012fb154fbe7efaa640758103f3b1ba01a9Virustotal results 25.00%SilentBuilder