URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/216ZVOKXLK/PAY/Business which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:57392
URL: http://ultigamer.com/wp-admin/includes/216ZVOKXLK/PAY/Business
URL Status:Offline
Host: ultigamer.com
Date added:2018-09-18 11:14:49 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-18 11:16:43 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:2 months, 2 days, 5 hours, 37 minutes Bad (down since 2018-11-19 16:54:02 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-19PAYROLL #18906HCMOX.docdoc 086c567118851a68bb669dec660860681a9e1379038f61ec3a71f7ae335fa362Virustotal results 26.23% Heodo
2018-09-19SWIFT #8943UY.docdoc 2a62f453555053cafa8d3ecce082c0bcd83171be76d79e9177b9bff70be01195Virustotal results 26.23% Heodo
2018-09-19BIZ #96286BDLBG.docdoc 225b8bc347307912cc0da70b1060fc2962839ba08a21ca3a2476ab2bc7400928Virustotal results 46.67% Heodo
2018-09-19BIZ #562859RANH.docdoc bb8f4ec84bd958bef701ed23674fb0e7d60bf8ae0ddd802f0928ed2a0fbf92c4n/a Heodo
2018-09-19SWIFT #9882112FFHV.docdoc 26d94d770779f8cacc1e3f4ffd28eda3b1373d71ec73950b702de38f15c5b025Virustotal results 47.54% Heodo
2018-09-19SWIFT #6PWZJ.docdoc 92db91577a4b1926cf181729ddbfbb61f16aef8520aeaf56a4a4a6d5c7ba3c1dVirustotal results 44.26% Heodo
2018-09-19SEP #24PVGJSZQ.docdoc 82b649d074063f4e07887337e94459474d0cbee28627802c8f2022c58fa8414dVirustotal results 46.67% Heodo
2018-09-19PAY #66094XBNB.docdoc db06680ebb82a6d11d5b1e282386153d61163ce88c28d56c053cf302c60f131fn/a Heodo
2018-09-19PAYMENT #60006COKFYX.docdoc ca27cf01c41fbb29d465cb6db77208af9514ac80a4c308685b4c9548febec41cVirustotal results 39.34% Heodo
2018-09-18PAYMENT #05861UYN.docdoc 87ec5f127d0eb913dcc9228930fca402403b5911d7e7329af9ffc4e6f0494173Virustotal results 44.26% Heodo
2018-09-18BIZ #4753095YH.docdoc 32c8ab0b2762bb7c2ed5510280c9d880aee17e46f46bf652a12b6568de97fe8eVirustotal results 45.00% Heodo
2018-09-18SEP #73720JUDYP.docdoc 11c4c9955d77e8c297320755568bfeffd73e77b2f8f6d516aec73bfdcb4ae5c5Virustotal results 42.62% Heodo
2018-09-18PAYROLL #137QWLMOHKA.docdoc fdd5b1d003aa632d667c4169616603e87eeeadf004e5385ad8ec31735a3af47fn/a Heodo
2018-09-18PAYROLL #1950075J.docdoc 3863a43d951e8365e96d5d982a3cb178b260c608a904c378d048b8715406802fn/a Heodo
2018-09-18PAYROLL #746168ZZWSAK.docdoc 9055acc9a6854eb9969d767ef27771706e17983c4612e73a28d6f358e7ed8a96Virustotal results 27.87% Heodo