URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/448770WLY/SEP/US/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:55405
URL: http://ultigamer.com/wp-admin/includes/448770WLY/SEP/US/
URL Status:Offline
Host: ultigamer.com
Date added:2018-09-12 02:13:23 UTC
Last online:2018-10-12 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-12 02:14:49 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:1 month, 0 days, 1 hours, 30 minutes Bad (down since 2018-10-12 03:45:17 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-13PAYROLL #48XWMFHFQ.docdoc 8870a62f875161882a0c93807ccc85209554a068953ae16190484414b427b173Virustotal results 36.07% Heodo
2018-09-13PAYROLL #95969I.docdoc 30594291490a1928a7bf89f633c88b3e8bb41c4ae795156309a0f076652d072cn/a Heodo
2018-09-13SEP #5387670IZ.docdoc 1316c887d94e24f942b882ecbe7314ef4746e2800122b27bb0086e8aacbb8b00n/a Heodo
2018-09-13SEP #770944KJJUPUX.docdoc c64c8cb54c57849ca6c0d5a741e0726e4337b3df8dbd389e912c9a7899e3b311Virustotal results 31.15% Heodo
2018-09-12PAYMENT #1319TAHXRAKN.docdoc d255e74d39fb90e116b46e8ae8a9285ebf292696285a84be8fb17bf3891a2da4n/a Heodo
2018-09-12PAY #356605LGLYMQMW.docdoc 9115ac3af709e3d318f6ffe826b06d6c5a168b9e336501d78f0513bc8e00b0c5n/a Heodo
2018-09-12PAY #7199467JMHG.docdoc 961a7252c607c4675cfda69848006780ee9886b7d011c30cbe4aaae3b244abb3Virustotal results 31.15% Heodo
2018-09-12PAYMENT #9RWXXCD.docdoc 4bed35a9bb290c3f8cc8fe5f9e07c2564df7d05339c4e014d9f841596a8ab589n/a Heodo
2018-09-12SWIFT #931EGZCQYT.docdoc b916b14fde0e06e50cacca99605db7008f90b01ad4203b396abf717cc3fbeaefVirustotal results 28.33% Heodo
2018-09-12PAYMENT #64TADZE.docdoc f1e3ddd28a2200347dd2d366ac744affdd44178624e8ea0b9f893403faa03407Virustotal results 28.33% Heodo
2018-09-12SEP #58695N.docdoc 4a1940aba467e741a2e6bebb602ea77ba0d07a0bf1040a9ee589da19032a2debVirustotal results 27.87% Heodo
2018-09-12BIZ #0426QM.docdoc 834d2c131a08577c53405dfccfa2f79d14cc1423a2ca55eb708c7e7876bd0872Virustotal results 28.33% Heodo
2018-09-12BIZ #3695LCC.docdoc 94df0548c49c02344e33f971d5b03449afc8d9423c0ce84590101cfe0014633dVirustotal results 27.87% Heodo