URLhaus Database

You are currently viewing the URLhaus database entry for http://www.hekahealth.org/wp-admin/common-vVPDPyaOB-9RH1Np8dn/385622-ypBXM7-profile/hHr2s-h19xI26ia/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431409
URL: http://www.hekahealth.org/wp-admin/common-vVPDPyaOB-9RH1Np8dn/385622-ypBXM7-profile/hHr2s-h19xI26ia/
URL Status:Offline
Host: www.hekahealth.org
Date added:2020-08-13 01:08:35 UTC
Last online:2021-03-16 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 01:10:04 UTC to abuse{at}a2hosting[dot]com)
Takedown time:7 months, 5 days, 18 hours, 28 minutes Bad (down since 2021-03-16 19:38:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15Mes-20200815-6569.docdoc e8897e08793bf50e10da9a1580611e1c307bcd4e1f829a20066cc6ba0dc85ffdVirustotal results 42.11%Heodo
2020-08-15FILE 275.docdoc 29c27429a81caec5cc9d25cf7d663dd6747fa92569b49471b5c967d29b464260Virustotal results 41.51%Heodo
2020-08-15Rep 2020_08_15 FN8009.docdoc 4e43c1bccc2a042dc04313c13767fe7198126d875df525d57496e7b75453261cVirustotal results 40.68%Heodo
2020-08-14Rep-D2642.docdoc ba0039933254ee8ce9ef82399c953656984aae076ee36fcd0427f0fe2a2f89e9Virustotal results 38.98%Heodo
2020-08-14mes 04098.docdoc 9517fc7b84b22b3d4f23e53877062e2d46f1491e927b91eea03a9f3fe2dc5571Virustotal results 38.98%Heodo
2020-08-14List_2020_08_15.docdoc 95a85c48a77b0f285d874d96d852096d83f8275c4294627b68cc39f205ec00a6Virustotal results 39.66%Heodo
2020-08-14Rep QDC060.docdoc 2c50f621efded90cba64805311afc4551d077fef0ac40824b8384ad4118640a9Virustotal results 39.66%Heodo
2020-08-14Rep QDC060.docdoc 2c50f621efded90cba64805311afc4551d077fef0ac40824b8384ad4118640a9Virustotal results 39.66%Heodo
2020-08-14rep_14858.docdoc 67362ce243ba2443b124fa28206b9ab3c3915306cbce4b0b7d4b0c99532f6f56Virustotal results 37.29%Heodo
2020-08-14File_20200814_RBA1490.docdoc 665456af44fc843e545d1937baeefa7a85f67eaf4b0c1254adf627ceb4024372Virustotal results 38.98%Heodo
2020-08-14Inf-2020_08_14-18700.docdoc f21ed9b9cd121a9942d00b83ac52827e84b6c7e0dd212b7799875e347129dfe5Virustotal results 38.60%Heodo
2020-08-14REP 2020_08_14 920799.docdoc e6385a2fb59fe1f8ccea17205ad247594d5c534313e0ca2be5c37d65c3e818a0Virustotal results 37.29%Heodo
2020-08-14arc_20200814_DO664877.docdoc 945f2547c53d007bff36bfb5121b009619f750fb41314b856a1722535aba81b7Virustotal results 36.84%Heodo
2020-08-14rep W03084.docdoc ca892e2e1fc6ecc27842bda8c95ad80e56f74fa8721ace19c21213c09144492eVirustotal results 40.00%Heodo
2020-08-14Mes-20200814-JT54935.docdoc eb605964379dfca49f04738e67d5b2a7cd61450d1d49e328517a5cfb622b66c0Virustotal results 30.00%Heodo
2020-08-14File 2020_08_14 A5589.docdoc 41cca7a2a77a1322b45971d8df6561e438ff25268996c45a50912c041397dc15Virustotal results 30.00%Heodo
2020-08-14list-20200814-23279.docdoc d7d0bc90406ac2e4110cb71bf2793bff657e01d0a25b48944bfa75e14855f84dVirustotal results 30.00%Heodo
2020-08-14file JK755105.docdoc 2883a855a5d3d792060cb4da7861c9f198ad05183837025afd773345603fb9e2Virustotal results 29.51%Heodo
2020-08-14REP 20200814.docdoc f8d9aeff9c3ce77dae1ba129171de9f937a96e0b2428800091c0336bd58ee6a0Virustotal results 26.67%Heodo
2020-08-14ARC-20200814-JS755.docdoc 6e679288085db07da2e862c6fb064a2e55217e160f6659bb094c39355f86ff2aVirustotal results 22.95%Heodo
2020-08-14File 2020_08_14 IUU7476.docdoc f2b4d61b73b6fb5d1a8f6b6fa622f72924772d9591ec4674f70e1a1a56a229e8Virustotal results 21.67%Heodo
2020-08-14mes 2020_08_14 FE2840.docdoc 2047b7af8a019340890cac77368ae9bc2ddb3d2536eb35e0ef289f84c5c9f4d7Virustotal results 21.67%Heodo
2020-08-14doc_0730.docdoc 96cc7696696c8387532a6e6d5875dea4633d193b06eb9e588fd96375fd45c519Virustotal results 21.67%Heodo
2020-08-14File_20200814_TPE549396.docdoc 3d1486ce24783f11fafd7742a4be89b506a618c8d25c948fbf3de40868e22d71Virustotal results 22.03%Heodo
2020-08-14list_QU5058.docdoc d4a88ca54a68e1fe084066e4c30180a8ed63f914b073e6135708bd453bcc8587Virustotal results 22.03%Heodo
2020-08-14ARC 20200814 TBG5335.docdoc 581a3f67d3fde31dde0091a5d5dfd2f01cafa1c0e7436afa207dd5d893efdab4Virustotal results 25.42%Heodo
2020-08-14mes_2020_08_14_804.docdoc c8abcb9037593d232f45f85ed6bf489767afe3a6bc0fe9e04b2d94ec41b0cadaVirustotal results 25.00%Heodo
2020-08-14ARC-8520062.docdoc d6028f2bb96365cce05da417a123515321309850764b2f428a6ef433b865a0b5Virustotal results 23.33%Heodo
2020-08-14Doc 2020_08_14 MJ740133.docdoc f3c5012d1e34317327c27a31d0455e2313369e0be8ed7e4c84fae2eb8fde931dVirustotal results 23.33%Heodo
2020-08-14file 2020_08_14 5809618.docdoc 0a2dc95d0fbd8d2807c7a36ddc4f5584685be3dc2bdfeb3a1320fb5b93ec6719n/aHeodo
2020-08-14Arc 2020_08_14 ABO70475.docdoc a2de797ad23c2211a80a0f83b3ee774fa17931ce941a60511d850b1ebd3e4aa1Virustotal results 24.14%Heodo
2020-08-14doc_YL963799.docdoc 783a766ff6d8b06f0050f051c16b04cad1298697c81bbaeee5d8fcb014a60a29Virustotal results 23.73%Heodo
2020-08-14FILE_WTE621.docdoc eb8626c09f81f7723ee7afa0cf39e78db7be79b5e5522f82ed7c116eb5fae52fVirustotal results 37.29%Heodo
2020-08-14Rep_20200814_S319735.docdoc 3dd12ed62a3b89ed3d384f1e58d1ec2ecc0901ef17ec4738002d9da80818e148Virustotal results 39.34%Heodo
2020-08-14dat OJ6389.docdoc 29489efeb7ae7bd57c8cbca798da5a97deae5630ec298d8c5c71dfcea1eac7c0Virustotal results 38.33%Heodo
2020-08-14Doc_20200814.docdoc 750f4237628ffd460893c6534883f476f6d461970961beb9c1222b05b59d2c2cVirustotal results 37.70%Heodo
2020-08-14file_2020_08_14_YNA6812.docdoc 6280278fef02126376fca03e39598bb3c17632cafd9fa99d26694b43c73da6c2Virustotal results 37.70%Heodo
2020-08-14MES-20200814.docdoc fe72004e6a838fcb078f8b14b9e31e68d627ab0aefdf9bd24c5e9db91e96f4f9Virustotal results 36.67%Heodo
2020-08-14Dat-20200814-QBN483849.docdoc 2465fb97adc0bcfd2852bc97bf6a929405c2b0c8abb85b57d294befdefbac099Virustotal results 35.59%Heodo
2020-08-14Rep 20200814 24290.docdoc 553b01cbb5adeea086cef71eea63ab8cfa4cdee6a75389a35d4be08a0c2a209cn/aHeodo
2020-08-14Arc_20200814_127.docdoc 0512dd4092177778885827b440a58af8d2f3b198cdbfca155a01c83363f39c94Virustotal results 36.67%Heodo
2020-08-14Arc 2020_08_14 Y1175.docdoc efd285d45835c318c4e079fae4840399a89ae40bf6134dac6cef9e7483e9680cVirustotal results 36.07%Heodo
2020-08-14REP_2020_08_14.docdoc a845ac9f688067ea1bfa082b06f32fe0b8974c3a4d2145261e4bb9bf78f3b9cfn/aHeodo
2020-08-14ARC 5066.docdoc 24cffd9cba643e90804ca8b7c8cfcc717ef8ae85ef64485427c51d320333baa2Virustotal results 36.07%Heodo
2020-08-13Doc JZ7457.docdoc c660380b581ba0b1e12f563b83f542961d51fcb0b0e7d052a1b5dafe83718eceVirustotal results 35.00%Heodo
2020-08-13LIST_64216.docdoc 3efd4a08c50243b09398358b273ba94d87c862c3d35c87c3ea053efbc6de000bVirustotal results 35.00%Heodo
2020-08-13file 2020_08_14 378.docdoc aa253dd86d00217ef0405e1632fe822af17023b8277078b08be3ecdae72d78daVirustotal results 35.00%Heodo
2020-08-13List_2020_08_14_A128.docdoc faca9557e0e2d11bc5ddfe5cfe01d56b2cf10391636d75a751252ebd059ca753n/aHeodo
2020-08-13Inf-20200814-MZ355.docdoc 8c9ad53dec636d785fb17d8d2e71a59498898c587e80673d8213ce50eb382e3dVirustotal results 36.67%Heodo
2020-08-13FILE 0701.docdoc 3cfb59dba8f521746b10428aac0d14c54bc21e8e3998893d0a2637f0b0abfd48Virustotal results 36.07% Heodo
2020-08-13Rep.docdoc e7de050d71f9096090112f6d185f4e3b1032a171ff6c6799f689f55ea154f008Virustotal results 35.59%Heodo
2020-08-13LIST_2020_08_13_999.docdoc 5bb4b84296ec60184ea017e657bcea6f6d3acaa986abdfd64cecbbd4ee027731Virustotal results 37.29%Heodo
2020-08-13arc 2743383.docdoc b70ef5272311329771dc7aa2f6e62affd540bffa733e6f8360abfaa99e14ff07n/aHeodo
2020-08-13file 20200813 LXY5105.docdoc 46927454721c5e3fd90b2fee4870ce3ed1164f837680278f19478136a5480023Virustotal results 33.33%Heodo
2020-08-13LIST_2020_08_13_WI266.docdoc 7af42baeef06be27d7adf0373ae6aa739ba3593a52081a9a767173bdd3704dcaVirustotal results 33.33%Heodo
2020-08-13Mes 46212.docdoc e32af16c5d48bcde511a70c71dae7d02665e6845d145ad8c0348bb203eb762deVirustotal results 32.20%Heodo
2020-08-13INF-2020_08_13-8324714.docdoc f4ec266b14464dadad86630e4f028e4e59dd7e7b806925e1ea65fa9e277abf11Virustotal results 35.00%Heodo
2020-08-13Arc ZM498.docdoc 502df3593c8baaf12f4fe79b927203836c872f0b7d6f11b7084cca840dc05255Virustotal results 32.20%Heodo
2020-08-13Doc_HFZ86000.docdoc b67ea7bd82a7a8cc26c3587fd81972d4475a5c342f5980f400a1c8184a142867Virustotal results 30.51%Heodo
2020-08-13dat.docdoc 92ef252d93dc57fe3b08c5ae7b0d8a6054d85e3b6f378af68a5c184099aa75e5Virustotal results 28.81%Heodo
2020-08-13Doc-N1556.docdoc 57270c211c92893639f45356ac942602a73f44cd8d9f13538b2afd2e300ea475Virustotal results 28.33%Heodo
2020-08-13Mes-20200813-A47046.docdoc e946007ca584996c15a16e621741968ac65868ef3d76a451669f37f0d0be1d8fn/aHeodo
2020-08-13DAT-LBJ523.docdoc f67568f08758378dc851f5550899115ef41b18c6a7e92facb84fd0a33a2af287Virustotal results 28.33%Heodo
2020-08-13mes S60235.docdoc 4d9fb0fc21364011b0155c51ae24085a4371dfad9f32a0569e54d330fdf068ccn/aHeodo
2020-08-13mes_7474.docdoc 106c30e31f5d9ba2f49a5ce1420373a4643199884361a606b0553b9d3535d74aVirustotal results 28.33%Heodo
2020-08-13FILE-20200813-OY53204.docdoc a8a916f66d089d2a2c23ed7f30163860cc91269fb71b2415123cd57e3e424593n/aHeodo
2020-08-13doc-20200813-CI584236.docdoc 21daf21da8f0b098290789d2482e138e7d7aa4cee35835b46dd8684136aa0a2cVirustotal results 30.51%Heodo
2020-08-13Arc-2020_08_13-R1195.docdoc c4d5504614a89515e076eb3766121b4c161bd5c5f3eba280505f77b7f7a69629Virustotal results 30.00%Heodo
2020-08-13FILE_20200813_1591934.docdoc d111f7e51281671a4be10bc8809880ae95ecd11d99abd63fc1ad6f85395ee191Virustotal results 30.00%Heodo
2020-08-13inf-20200813-3065.docdoc 9f729a199518aff47368826d6036e6de95ad82b7d52e78e2fb268a993fbe7634Virustotal results 29.51%Heodo
2020-08-13File-2020_08_13-SP45924.docdoc a394f307a1b2d631b8a4be1518f22884983b1ab8d5bd5e922c492a92026752d5n/aHeodo
2020-08-13file_20200813_476.docdoc 7c1ec9b4be7e6c0c420ed6c2788fe96b85289280dc2a9631f084f6223d03a440Virustotal results 30.00%Heodo
2020-08-13Rep_B058037.docdoc aedfbb4721ad66a54bdcee74a01bec2eff0a704e45d508a6625bc9a574266b09Virustotal results 28.33%Heodo
2020-08-13File-I841689.docdoc 707f785846ba34483b1616e5e49c1f2795e9fb110072d0c939d40b0e3ef8b5c3Virustotal results 28.33%Heodo
2020-08-13Mes 034.docdoc 8e34aac321039ce22c7bbb89b61257a397013e7b62607102bea64b2fb1f61960Virustotal results 26.67%Heodo
2020-08-13arc-20200813-438451.docdoc 76bb490090bed7074824b7b620db247726602318c7acfb9e1c16861b79bfdf3dVirustotal results 27.87%Heodo
2020-08-13Inf.docdoc 48fbb5d57c3837b61bd9326f28dd064e51928b1038fa735a0c28a99342bad063Virustotal results 26.67%Heodo
2020-08-13FILE-20200813-329660.docdoc 21c04e61b8204b3b63d3420fcf570b5d7d063338639fac037a6748df5386e1a8Virustotal results 27.12%Heodo
2020-08-13rep-2020_08_13-RK3884.docdoc 5c70b1d9be2e62d3cb581708789ffcafdc47ae8733f09039db0c3c7bfe9041d9Virustotal results 51.67%Heodo
2020-08-13rep_2020_08_13_IV93794.docdoc 57fcedf7b710607daf3ff9d1d3f81b02e5597d6a760e10c3af3805702f2e2ec5Virustotal results 51.67%Heodo
2020-08-13dat-2020_08_13-4492.docdoc c58ccc775e7c2333d87ae2d0e8b965a9c633a1eebb558d4e153f2ed1a7cb63e7Virustotal results 50.85%Heodo
2020-08-13arc_20200813_3561245.docdoc f47ce1003a5f4843cba95eeba9afc1b4a80c87ab8ff25fdc351957e2d522f123Virustotal results 52.46%Heodo
2020-08-13dat 2020_08_13.docdoc d16cd96a6382c743e97444d51967f3d83c72ca0618c6d92facad07211712c9beVirustotal results 51.67%Heodo
2020-08-13MES_2020_08_13_EZ3402.docdoc 34b90b804ac07f37b48a7437f520d80dd3efe9bc79c96c722240c63d9e457164Virustotal results 51.67%Heodo
2020-08-13file.docdoc c153114c19a5a3f46328353928ee45bec771c3bee71b6fec9136c719ceef7e2an/aHeodo
2020-08-13Dat 20200813 43208.docdoc aa4969a431b1e23a26ae69f514a91ed3d887c6c0058ac592682a09f3db297487Virustotal results 53.33%Heodo