URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ultigamer.com/wp-admin/includes/Y3M2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:38977
URL: http://www.ultigamer.com/wp-admin/includes/Y3M2/
URL Status:Offline
Host: www.ultigamer.com
Date added:2018-08-06 14:44:07 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-08-06 15:02:10 UTC to ip_admin{at}csloxinfo[dot]net)
Tags:heodo link Pony link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-0714.exeexe 4e473457ea8eea869cc68754ddc1aca54d0343e912d16276a7ec7da023a16ffeVirustotal results 27.94% Heodo
2018-08-0761626965.exeexe 763052f95f73f5d608903f9b372c1dd4fae589a17dab9da93d78a369535f745dVirustotal results 22.39% Heodo
2018-08-07590332.exeexe 52dedf3a1d9b513e352e6664a7a14cb1bbaa6b0e1032702d34feb8aef0793f4bVirustotal results 16.67% Heodo
2018-08-075396.exeexe 1ff85d197b6d78b9ddf991c6dbda3b5f5f4903504c723a82f8d8d3033a5306bbVirustotal results 21.88% Heodo
2018-08-0711207269.exeexe 1bed7c2bcab3415b5c18fd003f408a16ea5c1f9d7c52efc989e315c0242064b3Virustotal results 20.90% Heodo
2018-08-0760.exeexe 05b4d7e301295105488730f41297b54e1e7e50e5dbac2b65d713ddc08520262aVirustotal results 26.47% Heodo
2018-08-077552785.exeexe 313ce9cd32e6aa6c9b17353342b3570aed40e1a43dafeffe9cd2a0ec2de8e815n/a Heodo
2018-08-075992014.exeexe f62bc87c7ca6abe040d71f565ab3b5d56098d0ed4582da762139dd0ba09427d5Virustotal results 19.70% Heodo
2018-08-078413482.exeexe 23c2378caa0dc4183569a7a7e2681ad11e885783983748dd0eabbca4ae77c3e7Virustotal results 24.24% 
2018-08-078951251.exeexe b94ba01b6301c2b407978f2f8ddaa2adddfa36c8669efa891eef0b83d80990eeVirustotal results 21.21% Heodo
2018-08-07731126.exeexe 13484c83184ff7ff173e47df65010ca06a5c439d2c28a868acc2403a85ea3b08Virustotal results 19.40% Heodo
2018-08-06339.exeexe be40fa90d021a68f26117a764c927e7a0ba009b523eb6556498249a9d48a5bb9Virustotal results 17.91% Downloader.Pony
2018-08-063.exeexe 5e19c03d8558a9d1cc02b767afce7e55522aeb889fc91dccf9c3a8b270c2b45dVirustotal results 23.88% Heodo
2018-08-0645709.exeexe e39af21cfbbbaa94e26d23a40d45fd20494375845a3815b80145ffed806ffa1dVirustotal results 19.12% Heodo
2018-08-0664746001.exeexe 131f0296dba34a98d3d79c29d095365885aa508b66645ccd5e698abb7c47361dVirustotal results 19.12%