URLhaus Database

You are currently viewing the URLhaus database entry for https://www.haekelheldin.com/wp-admin/lm/chuf3gz4e8xy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:441158
URL: https://www.haekelheldin.com/wp-admin/lm/chuf3gz4e8xy/
URL Status:Offline
Host: www.haekelheldin.com
Date added:2020-08-25 18:06:33 UTC
Last online:2020-11-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-25 18:08:03 UTC to abuse{at}dogado[dot]de)
Takedown time:2 months, 29 days, 19 hours, 27 minutes Bad (down since 2020-11-23 13:35:49 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27INV_76332457.docdoc f0ea286853f8400fbb5b1b42414974133b5b477aefa7003271be47856f8603e7Virustotal results 32.20%Heodo
2020-08-27FILE_88442961.docdoc 92bf7a3db0aa9463183baad64245f898f7dd2978f547f754f7418c2a5fb7f192Virustotal results 32.76%Heodo
2020-08-27REP_EPI_080120_SPP_082720.docdoc 72a047a55409445c1767467b0e67391b0fbdb99be5b2e6a5457df52c7e2ef398Virustotal results 41.38%Heodo
2020-08-27H_PO_08272020EX.docdoc 92edabdfafbef478611378e867cb3f462fa7f5ac106a8f0d5045627d04c4c00fVirustotal results 29.31%Heodo
2020-08-27BAL_PO_08272020EX.docdoc 63d5f79e05174cba8a5d193204e864185ebee87d45bb3c6e3dc4739ebd947d70Virustotal results 29.82%Heodo
2020-08-27INV_ZQ4769990867ZD.docdoc 41213a4adcc07029d82e0c00a9932eb28ea7e5c9a41934e40ee35de060f8ecfcVirustotal results 30.36%Heodo
2020-08-273090971161357207614335831.docdoc dca5bf3ec81849f15a96ff016d862539ecab9711026c0dad8dfb63e8fcd6f256Virustotal results 28.07%Heodo
2020-08-26BAL_8740879932077249041.docdoc 7a082d2d846a53d95bf86c4806bc6ace013ac04f1fa8750c17728f64726e47dfVirustotal results 31.58%Heodo
2020-08-26WAOBT86Y.docdoc 1c50d88604610dc28e6769e8c4d2526a24ba934e3b01108514edc13f68892451Virustotal results 27.59%Heodo
2020-08-26DOC_LG8NBK8F.docdoc 4c68239cfc8d7393d3f5db18ae6341b775205cd878f1c0ecd892acf4accd8f08Virustotal results 27.59%Heodo
2020-08-26DOC_07230743474732400748.docdoc dea98698a907a95e646de347286e7bc23d8d095022a89d3e4dc22b1652eaabadVirustotal results 25.86%Heodo
2020-08-26REP_ZYM_080120_NWL_082620.docdoc 321fcb0d8290d27addd409b3f1c25b93921522d78b971991206abf1b592dd0b9Virustotal results 27.12%Heodo
2020-08-26DOC_PO_08262020EX.docdoc e2f93f504fd4eaf83abee9ba616dd2ff6264f7805737a5556899e37883c7cdc0Virustotal results 28.81%Heodo
2020-08-25YO6703697344ZQ.docdoc c83c6353d36706d9ede8b73d387db5ea74ea2977900f849d802d7cf17669c266n/aHeodo
2020-08-25FILE_PO_08252020EX.docdoc 671eb437230d3a779fdd43549113542c76054cf1440e7d527886077a236775fcVirustotal results 40.68%Heodo
2020-08-25DQB70D0JUAZHR50I.docdoc 83633727d8affa87f9d3f901941aaea5b31abdf0ec6b80645151497345484f4bn/aHeodo