URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ultigamer.com/wp-admin/includes/US/Payments/11_18 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:76263
URL: http://www.ultigamer.com/wp-admin/includes/US/Payments/11_18
URL Status:Offline
Host: www.ultigamer.com
Date added:2018-11-08 00:00:22 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-08 00:02:08 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:11 days, 16 hours, 46 minutes Bad (down since 2018-11-19 16:49:00 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-09eFILE-69874715321806.docdoc 41a904f0fbccb3384f0cac45c44dd11428abb34f6c3280ec24b8c9cdc180c2b9Virustotal results 18.97% Heodo
2018-11-09DOC-5054559530.docdoc 9c1468cf0ec8794f7a75fb8537e1a42e24436bcf63298792eb62ff55ee517f38n/a Heodo
2018-11-09file-5690921808.docdoc 12b379ac95454c365edf299e087e861fbe8df739dcdb3d82b30dae3c4a201583Virustotal results 16.36% Heodo
2018-11-09FORM-3634478240604804.docdoc 4a455e0a53007d2bc3092d2ed1ba66ca53993255f154100d6e4675822aeff947Virustotal results 17.24% Heodo
2018-11-09form-044068804184.docdoc a4d420b57a6a78d801ec6dc6418c12b85035c500462766e14d3f53da1e0a0158Virustotal results 16.95% Heodo
2018-11-09doc-04376424119461.docdoc 741a12b3a2bc48ae7b429ea0bd15addea3580700b4402707cafe7dcab5d10b8bVirustotal results 44.07% Heodo
2018-11-09form-47038296011.docdoc cdc79aef87d547d7797c8f1950754c7943dc6da4d91604a1e43cb7f32346be73Virustotal results 39.66% Heodo
2018-11-09file-53864751362217.docdoc 12e9b711e546c9c1d12719740e48e599fd299db60f21126abbcf1b0495cb80cbVirustotal results 42.37% Heodo
2018-11-09Untitled-431776337861451.docdoc 385879eca94e5e8dccfab6fd036ff7472cc9fad37d2a8bdd561224495802caaaVirustotal results 40.68% Heodo
2018-11-09eFILE-2264841642948478.docdoc 003591243133d77d308b2aeabaa396dbb8287c60fecf6a7645771e10317d9e5fVirustotal results 38.98% Heodo
2018-11-09file-427270546677.docdoc cad49daaa3ca3d7bd46b472723c5cb9b19006dd13303e2aaad0231295ec5a650Virustotal results 36.21% Heodo
2018-11-09file-3273734565209849.docdoc eee7617113d4a7d6efd12c71027618c908f47aa4e4e96b19f4c1805c166fe876Virustotal results 36.21% Heodo
2018-11-09Untitled-239636086818578.docdoc 68e5cf10c297a7862c047d35228f9121d32a9d7012c9df0aa015e496e3fa434cVirustotal results 36.21% Heodo
2018-11-08DOC-2435944857.docdoc 1c942e4d87c93a6fa59065ac7eb5c76f6f6acfab25e5f8843beaaaf8229f328eVirustotal results 42.11% Heodo
2018-11-08form-465522191647137.docdoc e57f9b7ce52edba1ec74c19714e2a9baaeef40bca090b304ed2bb3704ca285c7Virustotal results 43.10% Heodo
2018-11-08Untitled-6890587649694417.docdoc e2572648abd3d970d1c2fb7c534913887f1d912f880c20281ca02e853fee129fn/a Heodo
2018-11-08Untitled-9861011224896.docdoc 45ac4e9600cd8a3a143cba0f4b655b82dff52867774f236194a35e6b21a8fe70Virustotal results 29.82% Heodo
2018-11-08doc-44719645855.docdoc a7e80c448efb6e22d4bbeed42add330ac4d581b42f07d5ccce9073b7298faa27Virustotal results 23.73% Heodo
2018-11-08Untitled-66244953489.docdoc 577a152093f7481d8d437e5826673a12692db008e1de00bd87d57d730e5ccf40Virustotal results 22.41% Heodo
2018-11-08Untitled-5573650046.docdoc 94f8a5d296e6c3d8dd9f4b6e770092a522fd0acec4134713d17dc0a0c257e7e4Virustotal results 30.51% Heodo