URLhaus Database

You are currently viewing the URLhaus database entry for https://haselkhiz.com/wp-content/INC/l9hfvK7WewiaJco7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:704254
URL: https://haselkhiz.com/wp-content/INC/l9hfvK7WewiaJco7/
URL Status:Offline
Host: haselkhiz.com
Date added:2020-10-16 22:07:06 UTC
Last online:2020-10-17 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 22:08:21 UTC to abuse{at}hetzner[dot]com)
Takedown time:11 hours, 46 minutes Good (down since 2020-10-17 09:54:53 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17LIST_20201017_947.docdoc 294c6f87d8514072c30988bd55dd643c5c018b9f9ae05b9db1a97d034b31e092Virustotal results 55.00%Heodo
2020-10-1743764MS 20201017.docdoc fd4a45974318a540bf249d7aa768f6d4ec1bb268bb05e5028935db34aff711f4n/aHeodo
2020-10-17Attachment_70507.docdoc 73c8e321733773d7413efd1447245567bceaac2f4f85447e1196884a898cbea2Virustotal results 53.23%Heodo
2020-10-17Dat-2020_10_17.docdoc c147f6f4d8e08ce92756aea055fb18dc3398e77ce2ba5a71bfa3d6eb5f3de750Virustotal results 53.23%Heodo
2020-10-17doc_NYT059.docdoc adbad3c068d4497ae8a6a18056cfc39fb152c2085f694dcace8e772cc1867f22n/aHeodo
2020-10-17MES-WC18870.docdoc 90e7a0a9f215c30d103034801a89e4b61554c48bff10a98df0d09257cfc716cen/aHeodo
2020-10-17Untitled 2020_10_17 67945.docdoc 308b5a0affafedcef7431861d7785ddf4db3314cf5e18d5fdbc4c0168cc63ea7n/aHeodo
2020-10-174313NE-2020_10_17-GD869198.docdoc 3fef345a1fa8f779f98589ca704dff21e59f8842175c3cdab8caeb16e5e61ad2Virustotal results 53.33%Heodo
2020-10-1744063533-7019545.docdoc 78f2969b92269cd9a3e1cc7003b0949f47421d551c323dbeafa94ad0a836bf34n/aHeodo
2020-10-17WF136_20201017_688486.docdoc fca525a70cdbc09d5adb7e320849a4e9958f5edb129e2accce15281a340edf54n/aHeodo
2020-10-17Attachment-2020_10_17-BSI2635.docdoc 49bfab81e7c83836e13d24a1c3e607ce00aa745e850f110ef848cf96ab0b5b30n/aHeodo
2020-10-17List-2020_10_17-JRX76569.docdoc c14604804cc32fb30b522dd9dff211839670ae27b989326efce1e69589bc9d36n/aHeodo
2020-10-17MES-20201017-3653.docdoc b5ea62943f3b8f07f8fc66e4e35a1d4d12022eae32ee901b016f48bf66fec06fVirustotal results 51.61%Heodo
2020-10-16ISR2531-20201017-MH67041.docdoc ff58a7b1e34b5e2de40fa9fa020ecc46b3c1cf0eedd40653e719e2fba15ce05fVirustotal results 52.46%Heodo
2020-10-16Arc-20201017-925.docdoc 39319e4e0e23653363b81024b93090dbf717424cc2dcc3c0291e6e56e3328ed2Virustotal results 51.61%Heodo
2020-10-16Doc_20201017_0480.docdoc 38a7276166183fb51e2c60c91165d139295de90105097cb4e24b077d3fa5d56fVirustotal results 51.61%Heodo
2020-10-16Attachments-20201017.docdoc 691b2fc6acbee6cf5fb93b6afad38eb2f61c4a211cb17cb3c617c2bdebd48f61Virustotal results 49.06%Heodo
2020-10-16UNTITLED 2020_10_17 KP39288.docdoc ea0d3c6f16a0b6c751479d44c06e9fc4ee4f7e47803b008c8ac0ea1ae93f5171Virustotal results 52.46%Heodo