URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ultigamer.com/wp-admin/includes/d which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:56562
URL: http://www.ultigamer.com/wp-admin/includes/d
URL Status:Offline
Host: www.ultigamer.com
Date added:2018-09-14 15:46:07 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-14 15:48:07 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:2 months, 6 days, 1 hours, 4 minutes Bad (down since 2018-11-19 16:52:32 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-10-2641.exeexe b95dcab39ea72933c9e83f08f3c8bcd2afa2cc204eb7089922642732b70837e6n/a 
2018-09-1541.exeexe 2d325563fc2ba18c9d4f30b5620c39f896895618fca7565aec90cf1d6994eb96Virustotal results 14.71% Heodo
2018-09-1596.exeexe f1c53e2633c11640b20c1d4f396ba5ed3f100631aa320af4a55c869c507ae5e1Virustotal results 11.76% Heodo
2018-09-157581206.exeexe cb617daf75b1bb7433794380c48f0be76a71b1f2d39921a91cc91085739926c2Virustotal results 20.59% 
2018-09-144593151.exeexe f03f072ff0c8d6c00581aa43ae3d9c1e4a088b18546356871eef25bc85cbaf62Virustotal results 16.18% Heodo
2018-09-14629.exeexe 134e71b5450138180c1b36bfa3e78f2b1e483372a474beff325ff9eaff8c32e5Virustotal results 26.87% Heodo