URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/Invoice which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:52363
URL: http://ultigamer.com/wp-admin/includes/Invoice
URL Status:Offline
Host: ultigamer.com
Date added:2018-09-05 22:20:24 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:41:24 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:2 months, 13 days, 5 hours, 8 minutes Bad (down since 2018-11-19 16:50:10 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-06Doc7619.docdoc 9e6516038675c07d326b0f14c1f4e5efa74d75107fbaddf6bda437de1d59ec42Virustotal results 40.00% Heodo
2018-09-06Doc26684.docdoc 8392cbca4a188b038a4ee855e738edc4c782725a2e8efc9ba0529eb8a7c965b9Virustotal results 32.79% Heodo
2018-09-06Doc02249.docdoc b5cf1eb2dfa9a64cfdbc05a292407200c105142e0f60845a2e90ef28f0883e46Virustotal results 26.23% Heodo
2018-09-06Doc528667.docdoc 2c9242cd7a484585e355d99629d6fe1f1c8c4ba7b4a3781a01b46294fb7e534cVirustotal results 27.87% Heodo
2018-09-06Doc968544.docdoc 33fbf1ce73cc4211edfe1d08d1ce0760832b553740a3a6b303cd98805c741ff5Virustotal results 27.87% Heodo
2018-09-06Doc06052.docdoc e91afeee2e46b2fdebff4484328d5cc158fbe39fc5dd1de0e959b7782b70ea60Virustotal results 50.82% Heodo
2018-09-06Doc6959.docdoc ad12b32bee745df9dfb325e78843a3e542c2efb198e7cca0ae4fffb98d0219b9Virustotal results 49.18% Heodo
2018-09-06Doc542063.docdoc 637e96bb25078bd74371cf279f4293a4af24908dc34652d2bf423b46ee1fb718n/a Heodo
2018-09-06Doc4208.docdoc 5665d6b361b6497cc07c5fdcca8fa957d42a8eb4fa52e5812716e36b2f208a13n/a Heodo
2018-09-06Doc44154.docdoc 1ce1209b507ae76b3f83ff6d382024f08b38ff7c4572baee00575c8fbed5cebcn/a Heodo
2018-09-06Doc2874.docdoc 3907d1a0e32137c281103d769f2466cc14e59361f110b312f9e930a9c743b05fn/a Heodo
2018-09-05Doc776249.docdoc 57d477727da145d35c4a2157b7b5f296bc1ea315aa9c0854e46bcfe85650b491n/a Heodo