URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/Corporation/EN_en/Invoices-Overdue which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:63567
URL: http://ultigamer.com/wp-admin/includes/Corporation/EN_en/Invoices-Overdue
URL Status:Offline
Host: ultigamer.com
Date added:2018-10-02 11:01:43 UTC
Last online:2018-11-19 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-10-02 11:02:18 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:1 month, 18 days, 6 hours, 5 minutes Bad (down since 2018-11-19 17:07:44 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-10-03Invoice.docdoc 222b7aa135c114fbaa3e1bdeaaf410e1067296592d2576ff5461b8a0ba8802ecVirustotal results 29.51% Heodo
2018-10-03New invoice 94AXW2443.docdoc d34ced604e76fbdbec6e62787449c8d32cf72dfbf18a29a815ccf9629f7e955fn/a Heodo
2018-10-03Invoice Query.docdoc d65d391153497bea0d1fe1d5aeae4ef8572908cf6e134adcbf96f15cc494483bVirustotal results 29.51% Heodo
2018-10-03Invoice Query.docdoc 1cedd14a129c1784a6216e72c1f98168de9ffa0d0df2f5367548bd396b03b890Virustotal results 29.51% Heodo
2018-10-03Customer No 527244.docdoc 8903fb1a6080570556c4217c3f329c66c3000b71163a5449047edfe701018456Virustotal results 23.33% Heodo
2018-10-03Month notice.docdoc f307a8dba269262ffd35549938a7c950e83ea534734a752dc385c3cd00594a1eVirustotal results 31.15% Heodo
2018-10-03Statement as at 03.10.2018.docdoc 1c8382645c92a3727199a84dfc792638b2fc26d5d4c67c95565fc32d25f60aecVirustotal results 31.67% Heodo
2018-10-03Invoice # 82XB66073.docdoc ba063a282be3c86d05ba721ab2635cd920c88038ce5804a2732b4f716637b286Virustotal results 31.15% 
2018-10-03Invoice # 2BW37720.docdoc 87e95573aa86825445616e4333b8878c6829ca9b125fc5947ddb80da3f900eeaVirustotal results 27.87% Heodo
2018-10-03Inv. no. 02GXZ075836.docdoc a1537896ddc2ee52cc1d06b82276ddb12a79c3477d49def47fe8585c12f38437Virustotal results 27.87% Heodo
2018-10-03Invoice.docdoc 1a5171472f15d1a715dbd9d8b108cbbed096404db6067b34e86936a5c603b50an/a Heodo
2018-10-03Invoice.docdoc cabf953f0c7b1ade83647ced760070d2d72e9f57dd9a2c7ec7e4177141849d7aVirustotal results 25.00% 
2018-10-03Accounts - Invoice.docdoc 35c3c740de000235df89a4eff4cd6e4e3b1bfedce77336850b75af2da7a9c51aVirustotal results 25.00% Heodo
2018-10-02Outstanding invoice.docdoc 615552f123608583a949a390c8fbae2842bd52926b3b143a6c47d8667e3ba3afn/a Heodo
2018-10-02Month notice.docdoc 50c1bdfa56a73c43368705071d2e19b58d2fe77f537feb32919b2b77a1323288n/a Heodo
2018-10-02Invoice as at 03/10/2018.docdoc f4adec35401a9340582e3dc9ccd784be3e296ca4ed88f04fa4fc387f56420f6fn/a Heodo
2018-10-02Invoice as at 02/10/2018.docdoc 6453be335f33d287158e7886518d28d888ab375e24abf7448f3231bc9c849635n/a Heodo
2018-10-02New invoice 06M791559.docdoc eccf6878b4f8e639376ffd2885ddc7099553586628894e15307f2990ad1b8494Virustotal results 27.87% Heodo
2018-10-02Invoice # 452W90839.docdoc e1704f6a5b22a4fa2e0322662af2bdc3267481185501393aab6cafe0707e7acan/a Heodo
2018-10-02Customer No 600387.docdoc 4625b4781c6715fe81d8f8831b056aca1f02c09ef5e9e6f0878bc871c7a7aeb6Virustotal results 26.23% Heodo
2018-10-02Outstanding invoice.docdoc 60f5330409200df34214c398d422b5e918bfff9ef6f36856d9397d314e5587fcVirustotal results 27.87% Heodo