URLhaus Database

You are currently viewing the URLhaus database entry for http://s-lifes.com/2vz3x6/EZfMEHypsxZVEpUiUkXWKzv/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992357
URL: http://s-lifes.com/2vz3x6/EZfMEHypsxZVEpUiUkXWKzv/?i=1
URL Status:Offline
Host: s-lifes.com
Date added:2022-01-20 12:03:05 UTC
Last online:2022-01-21 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 12:05:34 UTC to abuse{at}gmo[dot]jp)
Takedown time:18 hours, 49 minutes Good (down since 2022-01-21 06:54:47 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21774624463079.xlsxls 5a6ae409ad46c453172d047a1b1d7685cbdcc317653d90c6a968509d1c2229b6n/a Heodo
2022-01-213296875033595401375.xlsxls 245057c2c16d698dc5399ecd43ca39f9e0b35885a19cc42cd2650eb8e17d0c00n/a Heodo
2022-01-2182335683530.xlsxls dd6ee5ee1db29010e56a2b1adf5fda9553efacf03236a806283e094bbe44e275n/a Heodo
2022-01-21135953077077915921.xlsxls 199122387889e980d89870e33df8adc2dd5845eb81507a41b912b198e2e7a745n/a Heodo
2022-01-213277308429933911681.xlsxls 2c9af469fcb89bb2e93d1ac70ce0bec912b78d5c3cbadccc3040c18dd03f5e41n/a Heodo
2022-01-217336904466.xlsxls 0e9d63baddd3ed98bd278e9eebbe7724934f24c1e6d98d9734fb88180dbe9d41n/a Heodo
2022-01-213984415557139.xlsxls 13c3fec523cfe8ac14a7e78a8e2ca86dfd3b8bb8447eb7e733e7b1207de5bea6n/aHeodo
2022-01-214913657699712155.xlsxls dac57112411305935ad4318c4ff4f495b8b39f84f001b64d83ea3ae69a994b02n/a Heodo
2022-01-2195447341857067.xlsxls 16ddb6c2180f441a20da86176a4cd7bf7bf15099cac3e33f3b998d180b30fe60n/a Heodo
2022-01-21340025681836.xlsxls de46a17d9b06b85d587806089611fa41c60768c7767037b63ba868057b85e169n/a Heodo
2022-01-2150345812542031971.xlsxls 0dac6c23f1feaae5aa06f2ca15b939bde3b0392babe7cb38b91abc4112c0fea8n/a Heodo
2022-01-2181464347092427.xlsxls 9ad38c251b929edaf974d16b81d02e8b87ca16da14c4aa4eea44df09aa210c69n/aHeodo
2022-01-2140260061610.xlsxls d26fa50d28f1d5fecfbd935c7c439e19ed0336097938d366f8d2cb3e8c039824Virustotal results 31.03% Heodo
2022-01-2113957919000117389871.xlsxls d84d60a9e9f466b7e002480fcc1866ca8824a44db59b31dfb9477d8ffb21c4cdn/a Heodo
2022-01-219848670855.xlsxls 82dd39849f520450c56ac21901abda18f16d08294e0c9569e659ed9133781c7cn/a SilentBuilder
2022-01-211102622964949.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-21593183686683640578.xlsxls 5ba1e7e7b37d9efbafaaa5049277348349998f11e6252edb0aa7fcc37bf94c99Virustotal results 20.34%Heodo
2022-01-2111383279624216.xlsxls c853e3e650463ca03b11d37a51d45c21e90abb85fe410073c435eba0d168d28cn/a Heodo
2022-01-2135638598806.xlsxls 4520398e8aeabb1aed9cd4899a2ac014545d9ad9383959288cf2470f9c1c4731n/aHeodo
2022-01-2155753217063239.xlsxls c3deaaa5202a717b68951cf04c00e24200a91aeee0eceb58cc032a0471fbda36n/a Heodo
2022-01-21989122013869775.xlsxls bf377a8c8ae5170949a1ea2d2f8fb6d63a24839276a2fd63bc2a4525f1839a59Virustotal results 24.56% Heodo
2022-01-2162720864229.xlsxls 8bf7d7d4defb13d445be8e02c114fbe19561d60aefe633018efe1627b4cf3d24n/aSilentBuilder
2022-01-2145331237854704632.xlsxls cb72aea24f710a0d9b643de1e759ace18205bc20aa8aa7a91ecf20e556cad41fn/a Heodo
2022-01-2119692697015055431731.xlsxls 1f8c4b036377f2a61d53cb148ad29e36409e2248ccb66479eea7f3e5eac3cb78n/a Heodo
2022-01-2015559830730057864.xlsxls f968e46bcba287794933061736a68fae19dc3e579e41e54fe2712d4a8b3ed5a0Virustotal results 24.14% Heodo
2022-01-204399792332178.xlsxls c09ed0e640be54f6a8687accfd825500273641e5bf115439ab34b3e700a82434n/a Heodo
2022-01-2028651319019165.xlsxls 79ab6a611483efd4c9e4394ac5c6a91c458857820c4c4b9bdecf0cab92acf8f2n/a Heodo
2022-01-20435585158314813.xlsxls c3782f393e6dca8cbded5a7bbb73789792cd1bf807f4f71cd863b12992beda95n/aHeodo
2022-01-20459566101688907.xlsxls f0589b8808bb3a0c95faf63a4ce880ec2494cc4a88cd487d509bc8fc78b24123n/aHeodo
2022-01-2002704703060439.xlsxls 7758c1ef7b05f4e4e7e283eda2aba34801589c1ed656610c149a5b1a1a0b7fc3n/a Heodo
2022-01-20197336477905793937.xlsxls c670de986eae7da2182e35158c11f0354bb595a2cc5330ecf91bf8dcff6f32edVirustotal results 22.03% Heodo
2022-01-2041307223693376275.xlsxls 48fee052f0fa5361ddc892d4768321a00e5c80adabc60654488ea8fc1ffa135fVirustotal results 22.03%Heodo
2022-01-20355026112121.xlsxls 94ef78ad1bae59d96e38f0f9e0b1cdfa1533ea531ee1522be6adcb6dcf389548n/a Heodo
2022-01-2020430376218084388419.xlsxls 8a07b30e84df7c4db85691e055e4f39fb78621392b7a282b3b64d13a675e14b1n/a Heodo
2022-01-20442656509472047604.xlsxls a690bda4ad1bf1c1685a7d8a18d09327284fb0d9e74371f97e7c7ee7c6159efan/aHeodo
2022-01-2061584724219.xlsxls 8697b2c64ef08e5e4bd5ca43dd988dc5ab701d50fb022b74e7413b95a7dc7c02n/a Heodo
2022-01-200631485668644223284.xlsxls e8499e295f03f08e5b88e949410d47da75c2088340bfc860fa5c9d1e1ec915e9n/a Heodo
2022-01-2070747009802.xlsxls 06be4ce3aeae146a062b983ce21dd42b08cba908a69958729e758bc41836735cVirustotal results 27.12%SilentBuilder
2022-01-2065856141301603953225.xlsxls 4102ee23d580a34ad9a1790ea81e7d9739cae27b843165e0daa30b9450585db4Virustotal results 23.73% Heodo
2022-01-209110547567433238.xlsxls 71218d4b13d7c5ab1cd1583b1646b4e495f88b8acedb0376a89e02a11354d674Virustotal results 24.53% Heodo
2022-01-2061492729085985.xlsxls 7e95d5f31df3b9fc9934f70690ad92450133e8a8718b3cea37e558141aff2011n/aHeodo
2022-01-2072175901462479086162.xlsxls 1b56b512e143bf588017e0ef26bea37c85688b638e6b4aa2ca0d7a443ecf95beVirustotal results 22.41% Heodo
2022-01-205636460053866.xlsxls 518a575dd29fa59a36c26d6e3805495f6482eba8a375f084d332e9f1ea5e5d71n/a Heodo
2022-01-2072680107454.xlsxls b0e36478b864163f75bb15fa860f70b16605135a7a4138321cebfdb50e9767b5n/a Heodo
2022-01-20791352448279135.xlsxls da9d3b84063bde0697546e7a9b3e2ab5f8283698dfb032f76018f28b367146f4n/aHeodo
2022-01-207017278599613460.xlsxls 33bcc678281337839c7121adf32e1ea0fab2974709ab30d0099e4bbd147916b6Virustotal results 17.31% Heodo
2022-01-20756111202644169272.xlsxls 931c80255eb9df794e3bcf120d96baaf081417df4dbfc06a843d3999c9da8df9Virustotal results 27.59% Heodo
2022-01-20673867028398.xlsxls ca1baf60faa9486403587e0fac3c548db3aa5b6fb42897e1569020682499e319Virustotal results 25.42%SilentBuilder
2022-01-2065494781372.xlsxls fff3ac0f2ce35babb7cf736ec26a8374c8babd255489994937c41a8c005e5b46Virustotal results 22.03%Heodo
2022-01-204620601358.xlsxls e19b762e560008e23a2bd5ff0e0ed710b52c528edfe995fbecb484af29f68b7bn/a SilentBuilder
2022-01-2001880959276903.xlsxls 92f65a0fe643c1d601633944790e1263b9dc30881b77636627c624581aac4acbn/a Heodo
2022-01-2019937021785756.xlsxls 9713bd6e70b57a5f98a05f4c674192803b49850ec2f298546fc6fa8e5b473d5en/aHeodo
2022-01-20488966456326537725.xlsxls b3973d991b4f3e3870404c40bf59257bd40f4207f10dd5a6c34a8d4e29e0f7eaVirustotal results 24.14%SilentBuilder
2022-01-205307593826.xlsxls 4b90a0d2855800baf3485d8e0c38ec0e5aea83050ceeb38061af07eca0d16febVirustotal results 34.48%Heodo
2022-01-2097921476723823649014.xlsxls 67ded9d43aaf229f196c781c89724f196e14ad0cd7aefa70ecbefa2723408560Virustotal results 45.76%Heodo
2022-01-202581119856011.xlsxls d0e970149a72b878303b425cbeb058aac6d74f1b94b2c3e150e40ea7da2e9072Virustotal results 22.22% Heodo
2022-01-2090364868512780.xlsxls 77151a31805014e0dc372a02bdabcbe7cee6ce3eaa1cfe9646290a6969581666n/aHeodo
2022-01-20066961435043127244.xlsxls 6e5d0e25330f5d7d6c00aea7a32e5256546d31add66431519af4957ae9dca729n/aHeodo
2022-01-200937470659.xlsxls 0bcfb5ec55307b202d34f0fcdd61f1308ca007dad6288902b63fda00ba363d8cVirustotal results 28.33%Heodo
2022-01-207362053138.xlsxls eb2f4d9d99c1276b3b2687814ceb4805aa527e17b41fd2b7099d8ac693c2f6b8n/aHeodo
2022-01-2009229028090799.xlsxls ddefd9323bdbdba24723112237dd8654755e8a21e568c38d83b4e2b9849e4b15Virustotal results 41.38%SilentBuilder
2022-01-204463971532179744.xlsxls a9e347396807d827c3f8e30902f30d78960aad8712031fd1729637d1fd08f85bn/a Heodo
2022-01-2028869065900.xlsxls f52f03cb94b222c5feffb3c6b07bfebc90c8653f913fe06f27d60a15cd65a9f4n/aHeodo
2022-01-2089417470810.xlsxls 33093f1ef1d4b69b111e19172abc6a93e8c1e362905278e648819acace07e42bVirustotal results 18.97%Heodo
2022-01-207419837568.xlsxls 17581147f8499f2af73d7e6c3e66e18acaf2d4acdbec0aafa790384231cc9f8aVirustotal results 20.34%Heodo
2022-01-2011193408024.xlsxls da70bf56ce1781f9fcaf72fbe0a6a7c24d6d3ac5595d1274204f636b738a6de9Virustotal results 36.84% Heodo
2022-01-2002750258433444447231.xlsxls 32e843c35f0b39a4ff9d669a80da88322cdd4206caa24710e7fbe60db710597fVirustotal results 16.95% Heodo
2022-01-20601667466054376.xlsxls 22948141e8f020d01dbd92abd0eeacb3eb1d69fcf145fee4b65cdc395d309a57n/aHeodo
2022-01-20841534149959471.xlsxls fcf5fda3ac792863157c2b73fae2d1cd422d34220bd7ad41dcf76d7102cb93d8n/a Heodo
2022-01-201169881370075.xlsxls 4a4ee3f8e96ff14a83d4f61b0c94a52dab1ed3a0bcd3d588cfc52606df19d1d4n/aHeodo
2022-01-203389399190.xlsxls 54afab7495df32a4992bbf3b49a156d0701358881ff8c996345fa6788a80d789n/a Heodo