URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/JD5rDsBy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51098
URL: http://ultigamer.com/wp-admin/includes/JD5rDsBy/
URL Status:Offline
Host: ultigamer.com
Date added:2018-09-04 03:09:51 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JayTHL
Abuse complaint sent (?): Yes (2018-09-07 11:41:25 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:2 months, 13 days, 5 hours, 7 minutes Bad (down since 2018-11-19 16:49:00 UTC)
Tags:heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-10-0193858.exeexe 79efff8e32c47b3e21f6887e5eb8d32f015647cf234ca6127570db994aaef45an/a 
2018-09-0493858.exeexe 904fed4a2a037c0bb2f96391f4125614743b9bf5263c1340a42b3dd5ff9e5362Virustotal results 17.65% 
2018-09-0462163939.exeexe 25e5029b856cbdbfa1d12d8615f11d065b58d118ac183c20a0c9790dbe5614f4Virustotal results 16.18% Heodo
2018-09-0480.exeexe 483375f638c20330ccdc6425483a59d84dfc7e4da81f2a26363b7ee16a5a3cd9Virustotal results 27.69% Heodo
2018-09-047356.exeexe 1a98711944ba49025e047d62cdab907803460adfa11340bc70ab2b39896e6c5bVirustotal results 26.15% Heodo
2018-09-041.exeexe 2bb57582c8cbd528dd84cf21917785119b7e05035e2935cc0a0ea8c8dcdaa674Virustotal results 17.65% Heodo
2018-09-045021.exeexe fb4457707bd6e99b7d225d02078dda83fa8204766e63221e68530636004c8aeeVirustotal results 19.40% 
2018-09-040.exeexe f9bd6297685f057fae51eb7e6f003490229ebcb860c836d36907fe97b4101583n/a