URLhaus Database

You are currently viewing the URLhaus database entry for https://www.haekelheldin.com/wp-admin/invoice/24424027/lgrn5z-40/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445616
URL: https://www.haekelheldin.com/wp-admin/invoice/24424027/lgrn5z-40/
URL Status:Offline
Host: www.haekelheldin.com
Date added:2020-08-28 01:02:03 UTC
Last online:2020-11-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-28 01:04:02 UTC to abuse{at}dogado[dot]de)
Takedown time:2 months, 27 days, 11 hours, 49 minutes Bad (down since 2020-11-23 12:53:50 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-29K04 invoicing.docdoc 5df4f10d255d1733e9450ecf67d166c73f6f29bb36efe88d6093a31d31ce0ad4Virustotal results 45.45%Heodo
2020-08-28Inv. 087338.docdoc 418cd12b251bce9b75ac793c3d626440b35e8e6ef2002751114a27eb3a627d26Virustotal results 29.31%Heodo
2020-08-28K004 invoicing.docdoc e0e89d9c54afdf37e1a12ee7c9fd555e8e40c5a5c9eca4ad7bc97292dfa1d3aeVirustotal results 28.81%Heodo
2020-08-28invoice.docdoc 226ee760c3eb5d273f92e4d71d07b2e28f1699630549bd683c04e2fb904ec307Virustotal results 46.55%Heodo
2020-08-28invoices 784 & 18387.docdoc 4127b9c5397e1cb3b06cd7d59f06a08fef72ae8d071a7008d1159c12c0a7c8e6Virustotal results 36.84%Heodo
2020-08-28INV_635133.docdoc 20025223701d18c51c71b00a92affc112550598cefc9e5f6f94bcc6a62e39544n/aHeodo
2020-08-28PO# 08282020.docdoc 56385c138dcd6e1f59be2fadd0cb3e78305d5a8b74de904c00ca85d68aa84809Virustotal results 30.51%Heodo
2020-08-28Inv. 077509190284.docdoc 1e4247cd718e3c8e11d41fff2bcb19571e03a5ab290cd2073caf398878cb6648Virustotal results 31.03%Heodo
2020-08-28Electronic form.docdoc a03a331036791b2d25681114c722041029d9e995c684190654e5f664efe761a0Virustotal results 30.51%Heodo
2020-08-28invoice.docdoc 8a2ccbf2fd45902471ea5dcc116d258ca0ff53b4e7499fe76f00349f029d0570Virustotal results 31.03%Heodo
2020-08-28invoices 07046 & 48090.docdoc ba1bac226c7ba525e1b2706a7f0a7a0ddec1272db21044df1e28cfd777804a3fVirustotal results 31.03%Heodo
2020-08-28PO# 08282020.docdoc 7e0d6fc8bc7a69d5e27e2130c83b434512af52a5337145098c2426f62abf97eeVirustotal results 33.33%Heodo