Sites like these could be blacklisted as known infection sources, a qualification supported by the VT results.
And then they are like in these two instances: http://www.urlvoid.com/scan/he.87hxl.com/
Malicious Site: Malicious Domain Request 2 and http://www.scumware.org/search.scumware lists
WebCrack4_WebCrack4.exe ___ TR/Webcracker.A; h ___ TR/Spy.Gen; TR/Dropper.Gen; KmdKit/examples/basic/Synchronization/SharedEvent - ProcessMon/ProcessMon.exe ___ TR/Spy.9216.117f95118efe46f337d11c9/analysis/ and quite a range of other malware.
Re: https://www.virustotal.com/nl/url/a4e5a11ed2ca7dcf6fdbba93f82b155121bc84d6bf19
Nothing here: https://www.virustotal.com/nl/file/620663ad5427493af1d41cb1fd595faaa3ecd6050ffd54a682762c7f4b80386f/analysis/1381435122/
But alerted here: http://urlquery.net/report.php?id=6610680
and here: http://malc0de.com/database/index.php?search=he.87hxl.com
polonus