URLhaus Database

You are currently viewing the URLhaus database entry for http://hora.life/2em/L70FB1Y4VG/r44PDITlV4I752uTYt3J/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:587126
URL: http://hora.life/2em/L70FB1Y4VG/r44PDITlV4I752uTYt3J/
URL Status:Offline
Host: hora.life
Date added:2020-09-21 15:35:05 UTC
Last online:2020-09-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 15:36:36 UTC to abuse{at}iws[dot]co)
Takedown time:2 hours, 31 minutes Good (down since 2020-09-21 18:08:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-216040271_20200921_40580.docdoc 16be9e593507ba2ccca2de91d87b8784818450844e2dd0df7a54f2cd24f3b683n/aHeodo
2020-09-21FILE_2020_09_21_EK490310.docdoc f7e288414ab9e74bc1a11ae2adad7f9308badadd13b048f166a403029ce4c272n/a Heodo
2020-09-21File 2904677.docdoc 82fd021a09f56eb6c9c4129caab80c81c416871df51ed92e6649100c7373ff85n/a Heodo
2020-09-21FILE 20200921 I12257.docdoc 3d53561b3bf1124d38edeb67519a5abdf7951c6ff3abe5918b8458b5e9f94453Virustotal results 25.42%Heodo
2020-09-21Rep 409.docdoc 56cccdfa916393c8d85145450efab9f5862bfe379c2c38951956c6fd9592f53cVirustotal results 23.73%Heodo
2020-09-21INF X5472.docdoc 4b6f866b4d3e232b0bcb99a08d5ec72e495a8a4eba816436ac390f80fb01288en/a Heodo