URLhaus Database

You are currently viewing the URLhaus database entry for http://uglytup.co.uk/wp-content/lm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:296011
URL: http://uglytup.co.uk/wp-content/lm/
URL Status:Offline
Host: uglytup.co.uk
Date added:2020-01-23 15:08:09 UTC
Last online:2020-02-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-23 15:10:04 UTC to abuse{at}ovh[dot]net)
Takedown time:12 days, 2 hours, 14 minutes Bad (down since 2020-02-04 17:24:16 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-2525472008430557307.docdoc fa50ca8057cb27067c5df8ab26e14d030e4f0d8ceb4f6545bbfed65e32e81cf1Virustotal results 42.19% Heodo
2020-01-25INV_S9URPZRP4GY1.docdoc 592a0ef2e88f78e312bb01885b175903af622c96256d39f2186982f551c14c7dVirustotal results 38.10% Heodo
2020-01-25RP_HB8939596586HX.docdoc 10ccb0e6114b2932239292f029d8acd20c85228b81942340acfa1379b887ba02n/a Heodo
2020-01-24BAL_KN5768912515KZ.docdoc edf548758aeb6af93728a0d059f365608263d4677d096d5c0c826a221de425f0Virustotal results 30.16% Heodo
2020-01-24RP_95243331.docdoc b451ca27de63453de948c2bff97c43cfca5cd6c2f080aa4f260cb5c313b38db0Virustotal results 27.42% Heodo
2020-01-24INV_KBM7CLS5R8.docdoc c287370dbdee5d1a52938752c0f70684ec77c729ce78bb458366d49d4788526fn/a 
2020-01-24SW_PO_01242020EX.docdoc f116a0ae35beece0029de73070fe1f5c5a387cedb4e7668aaa08c8f4a7f1cd70Virustotal results 28.57% Heodo
2020-01-24DTM_24013694.docdoc 789f39cce8f34ef92a1114d703e66a8894c7d3025572c148161fa467d1b6fe81Virustotal results 26.98% Heodo
2020-01-24RP_96544246287856.docdoc bedffe567bdec300da442d0c24e30f94beca6e30401410ac906a60946b63fe9bVirustotal results 46.03% Heodo
2020-01-24DOC_3RUSQQ39C55IDB.docdoc 2c4b0f8d4c1eaa6adbac77b21a05ff32242cab116fc252c21c67fc0ab51ba110Virustotal results 46.77% Heodo
2020-01-23BAL_JZ9529956049CI.docdoc b4b863bb79c7f22ebbc9bd5183fd67c6b9e020e15eb75d24fbb6179a57e16125n/a Heodo
2020-01-23REP_MAQ20K18USQ.docdoc 70b896a95932fba098f1e50ae4c7f8796bd1636fe7f75ebcd5b690c986ab0c00n/a Heodo
2020-01-23ST_PO_01232020EX.docdoc 7ce67c2130cfdb654ce311489c29444f88fe55f5fae3d6f560506a2bc921d163n/a Heodo
2020-01-23REP_32201161.docdoc ce43998d0af42cb9a17bf220f9fe9418948e1e05c4b007cc306bfd2d4580d2a8n/a 
2020-01-23SW_33375421.docdoc f351e1457d7673a650544a0130b943fc10aba1ee461e398687a2d85fabb79129Virustotal results 25.81%Heodo