URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ultigamer.com/wp-admin/includes/935VFXN/biz/Personal which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:44976
URL: http://www.ultigamer.com/wp-admin/includes/935VFXN/biz/Personal
URL Status:Offline
Host: www.ultigamer.com
Date added:2018-08-21 04:46:35 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-07 11:41:25 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:2 months, 13 days, 5 hours, 7 minutes Bad (down since 2018-11-19 16:48:41 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-21SWIFT #36RKYJG.docdoc 7b22be4f6b51fb27c0e9301ead3c1bf12672b815948c0488fce9954fc38473edVirustotal results 23.33% Heodo
2018-08-21SEP #3377IWIS.docdoc 040383f170e9500a9bfbe6d3965c0aec1c7df837ea90d81c4a9ecfd9bb960d31Virustotal results 21.57% Heodo
2018-08-21PAYROLL #3627GXHKB.docdoc 183334930d4aefe32cc2b934254af4a98433b105ff7976bb97097b6b153fa878Virustotal results 25.00% Heodo
2018-08-21SWIFT #9757GTCACJ.docdoc 90f9324e19873c2bc351f67911c5731055f0942e8635b70992784d5795b3a0fbVirustotal results 25.86% Heodo
2018-08-21SWIFT #593540LSZ.docdoc 2333304ec374507c70bdbd996ca8d941cee93e115a98cb745baabaa52271fbf3Virustotal results 22.41% Heodo
2018-08-21SWIFT #0288114QQVLDBC.docdoc c6b5113c1f0a3e7d384c9bd6965ca6031402370066ed6cda277c88ab6d2b8ad7Virustotal results 21.67% Heodo
2018-08-21BIZ #8705916VSUEW.docdoc c6e82efefdbf69ae4a780592149e3b5f2ff2d9d6495f4887f604b9967aed9a5bVirustotal results 21.67% Heodo
2018-08-21PAY #9692884JQO.docdoc 351b5d7f01f09d5726fa50d3164965cd95a3a651b0028939ba92588c8b7aae2dn/a Heodo
2018-08-21SWIFT #2ENQT.docdoc 50abceb0847ffb5915421d68b4530c75caad14987ee88b9daa2b15ac87f01215Virustotal results 22.92% Heodo
2018-08-21SEP #2BQU.docdoc 2637411086e78305d213b5e5a70ab20c35c0aa5d61a00b0ab27952667fc14802Virustotal results 27.59% Heodo
2018-08-21BIZ #66MGX.docdoc b084388b731ff2950f86d4bf4a8dd606d04dfa04a88f2e21652138b8f80e9cceVirustotal results 27.59% Heodo