URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/INFO/US/Important-Please-Read/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:75037
URL: http://ultigamer.com/wp-admin/includes/INFO/US/Important-Please-Read/
URL Status:Offline
Host: ultigamer.com
Date added:2018-11-06 15:34:37 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-06 15:36:25 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:13 days, 1 hours, 16 minutes Bad (down since 2018-11-19 16:52:59 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-07Review invoice required.docdoc 63b7e49093fc817426ff9ba7b731ede3b58bc078d9e76e848b27de5e9e14dedeVirustotal results 23.73% Heodo
2018-11-07Customer No 325084.docdoc f31a737e4c8615dac72aca6d5157aaa8b522903d3956073f1ea86dc33b9ae1f5n/a Heodo
2018-11-07Month notice.docdoc a4b492840299c3435b6edadf96fd4b572f8993d97e3fda00d912ba554a84e8aeVirustotal results 20.69% Heodo
2018-11-07New invoice 2G3R87330.docdoc 8d74c083778f9511c01916d183301686ac09a7011bbfa8f744a5816dc244340aVirustotal results 18.64% Heodo
2018-11-07Customer No 944766.docdoc ec383b84e5038f061921a2a41b27d8635465826bce5636b21ede0fe061895972Virustotal results 18.64% Heodo
2018-11-07Latest invoice - 287528.docdoc b7b9e188fab49a592f794408b234660598cddf1b5a0124115d4f5d489f4c5c5bn/a 
2018-11-07Inv. no. 8JY67988.docdoc 42d8e974d69dd352062b784121f9df58b30a4b3aea684ce2f9fa418977b4776fn/a Heodo
2018-11-07Invoice Confirmation LH200752.docdoc fbe06d6ab0c7f51d6bd4bc7302e838b3cfc04c908e6cb550877c07e98b3424ebn/a Heodo
2018-11-07Outstanding invoice.docdoc d880ebb69507040f4364a0ffc83d3a2bd3247f58d3fc66dff4fb5856a3b1be7eVirustotal results 27.12% 
2018-11-07Month notice.docdoc 8927f1c00c44ffd58b7e6964ac3e8d4c6dd3541570ad419c34969ac1685630a9n/a Heodo
2018-11-06Invoice.docdoc 76ddd79d0ee84395b6feb5a11b97af610346b95ccd8f4b9a1a2ffd46d3f0e24cn/a Heodo
2018-11-06Outstanding invoice.docdoc e751449a27a5840aecae530d79ed9de9f619011b85e065006d3ccf5f7b960695Virustotal results 25.00% 
2018-11-06Invoice.docdoc 107b9121fcdaa53badabc76ed2ea564ac26a960b6630f67931ff9ea98f3d3814Virustotal results 24.14% Heodo
2018-11-06Inv. no. 468QF08507.docdoc a800c30c82a66750cdf1566e9dd71f66e1a5088fe14c0207d2146fc4cbad86a5Virustotal results 24.14% Heodo
2018-11-06Invoice as at 06/11/2018.docdoc 41f1d8d35ad8ef07e6528886081ed4ec7cfbf156ff7a791720a2e4e497e5a138Virustotal results 22.41% Heodo