URLhaus Database

You are currently viewing the URLhaus database entry for https://www.haekelheldin.com/wp-admin/browse/yyhc9465bw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452598
URL: https://www.haekelheldin.com/wp-admin/browse/yyhc9465bw/
URL Status:Offline
Host: www.haekelheldin.com
Date added:2020-09-03 17:23:03 UTC
Last online:2020-11-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 17:24:02 UTC to abuse{at}dogado[dot]de)
Takedown time:2 months, 20 days, 19 hours, 46 minutes Bad (down since 2020-11-23 13:10:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-0546905985.docdoc 2b7b0ff44457a586cf0ca88f5b8f4bee199a18d6c52e494b2ecbbe083c3baf5fVirustotal results 40.68%Heodo
2020-09-05AA5478378966JW.docdoc 5d0a19a1fe7969a9950c8d711f2e80d7203cce5287c039937b593fd098938701Virustotal results 25.42%Heodo
2020-09-04FILE_61388383726301336029585.docdoc 2f43042095548e57c08e93e9da55256337e669662c48bcae3ebc01a9b3113cbcVirustotal results 23.73%Heodo
2020-09-04FE3887966138JS.docdoc b5533222607313c1e5318c308f318224a53034815f0c64c398f7a47c3a022efdVirustotal results 37.29%Heodo
2020-09-04OEG_090120_VFV_090420.docdoc 9c3e1b5dbb4688d70bc0ef062f2996d616f5b751f53ef4b38143b85c9fb580a5Virustotal results 37.29%Heodo
2020-09-04HCX_65799539.docdoc ce3d5b240c3b0845c3c82b59c532f3a247a052e594251aa3a835719044fc8e75Virustotal results 32.79%Heodo
2020-09-04KCSCJV9D8VOUWFIJ.docdoc f19b7c3502d8e70e4a41fc4676cf0ba7a1de47cc19b1e961be4ceb8511119637Virustotal results 41.67%Heodo
2020-09-03REP_VOL0HM0LK6BCQO16.docdoc 3fc5c32aea12c66d06cdb30dab7f1e1cb7181efc4d2d6d9c91511d69e53f4a04Virustotal results 32.20%Heodo
2020-09-03P_JB1582701540VW.docdoc 239a7ae434b146c6144586fc720dd2e24209c1b5c3af1923fe94d4783f75732dn/aHeodo
2020-09-0347813661597.docdoc 98c7014278804aca02b1c513a3eb7ee6211544c28380184caef1fdb5a6481e2cn/a Heodo
2020-09-035040194937966.docdoc 6fdde19bdfda474a8a433f49503ee030792b3e69b4083392477de275f7bbc2dfVirustotal results 31.67% Heodo
2020-09-03DOC_VV6339452403LK.docdoc 055b666ab9ac2b2ec9d5b3989f9e6f5d988d05507dd3bd1a90a7e6a67e3b3f34Virustotal results 31.67% Heodo
2020-09-034H5JZ29VD13.docdoc f50133085cf408fa42e3568d8466e35d6ae2ceffb26ec78fc25041eb5e5d7c93Virustotal results 27.12%Heodo
2020-09-03DOC_Y6KEHGB.docdoc 4e07acebb70675f700532b03d4394ff4f7d0781363a5f189d193fcc9cd0a60c4Virustotal results 27.59%Heodo
2020-09-03PO_09032020EX.docdoc 0e1f9ddd8411617e908247ae7220c1e5bc747afcf9e9194cdf69cbd9ce1aa962Virustotal results 25.00%Heodo
2020-09-03L_PO_09032020EX.docdoc ef83bb095a3464475617dee0fa7ca6f291815a93a7c984191bcbd689b167cd3an/aHeodo