URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/INFO/US/Important-Please-Read which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:74748
URL: http://ultigamer.com/wp-admin/includes/INFO/US/Important-Please-Read
URL Status:Offline
Host: ultigamer.com
Date added:2018-11-06 07:36:50 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-11-06 07:38:17 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:13 days, 9 hours, 15 minutes Bad (down since 2018-11-19 16:54:09 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-07Review invoice required.docdoc 63b7e49093fc817426ff9ba7b731ede3b58bc078d9e76e848b27de5e9e14dedeVirustotal results 23.73% Heodo
2018-11-07Month notice.docdoc a4b492840299c3435b6edadf96fd4b572f8993d97e3fda00d912ba554a84e8aeVirustotal results 20.69% Heodo
2018-11-07New invoice 2G3R87330.docdoc 8d74c083778f9511c01916d183301686ac09a7011bbfa8f744a5816dc244340aVirustotal results 18.64% Heodo
2018-11-07Customer No 944766.docdoc ec383b84e5038f061921a2a41b27d8635465826bce5636b21ede0fe061895972Virustotal results 18.64% Heodo
2018-11-07Latest invoice - 287528.docdoc b7b9e188fab49a592f794408b234660598cddf1b5a0124115d4f5d489f4c5c5bVirustotal results 37.29% 
2018-11-07Invoice Confirmation LH200752.docdoc fbe06d6ab0c7f51d6bd4bc7302e838b3cfc04c908e6cb550877c07e98b3424ebn/a Heodo
2018-11-07Month notice.docdoc 8927f1c00c44ffd58b7e6964ac3e8d4c6dd3541570ad419c34969ac1685630a9n/a Heodo
2018-11-07Latest invoice - 667820.docdoc acfd3ae8a5156bb1e5ab9f15ad07c73ea3a43c4f32dee58563de17b77a4fc50eVirustotal results 25.42% Heodo
2018-11-06Invoice.docdoc 76ddd79d0ee84395b6feb5a11b97af610346b95ccd8f4b9a1a2ffd46d3f0e24cn/a Heodo
2018-11-06Invoice Confirmation Y709085.docdoc 4cca8f36876f82b661b852af672e1c1ef5532332e1ff25330f23f5a2a67bfb2fn/a Heodo
2018-11-06Outstanding invoice.docdoc e751449a27a5840aecae530d79ed9de9f619011b85e065006d3ccf5f7b960695Virustotal results 25.00% 
2018-11-06Invoice.docdoc 107b9121fcdaa53badabc76ed2ea564ac26a960b6630f67931ff9ea98f3d3814Virustotal results 24.14% Heodo
2018-11-06Inv. no. 468QF08507.docdoc a800c30c82a66750cdf1566e9dd71f66e1a5088fe14c0207d2146fc4cbad86a5Virustotal results 24.14% Heodo
2018-11-06New invoice 945O1704792.docdoc f486dca2a2004fb6aa8d16e446f002983e3bcb935269b1f8029c64e67d854a5dVirustotal results 22.41% Heodo
2018-11-06Billing Invoice - Job # 4941184.docdoc e4847906283f4facfaa7e97f2304935851223b5bd5c3dc0eb70fcdbd92733efdVirustotal results 20.69% Heodo
2018-11-06Accounts - Invoice.docdoc 57d24769c8dd4ea3ef673402fc8768d27f9d231ef22baf1d42dd648e8859b554n/a Heodo
2018-11-06Inv. no. 0ZZI22768.docdoc f3e187ebd0be4413d9495345935aeb63a025bb299c63b24787188a71003e5a5bVirustotal results 32.20% Heodo