URLhaus Database

You are currently viewing the URLhaus database entry for http://ultigamer.com/wp-admin/includes/US/Payments/11_18 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:76602
URL: http://ultigamer.com/wp-admin/includes/US/Payments/11_18
URL Status:Offline
Host: ultigamer.com
Date added:2018-11-08 07:59:07 UTC
Last online:2018-11-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-11-08 08:00:09 UTC to ip_admin{at}csloxinfo[dot]net)
Takedown time:11 days, 8 hours, 49 minutes Bad (down since 2018-11-19 16:49:51 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-09eFILE-69874715321806.docdoc 41a904f0fbccb3384f0cac45c44dd11428abb34f6c3280ec24b8c9cdc180c2b9Virustotal results 18.97% Heodo
2018-11-09DOC-5054559530.docdoc 9c1468cf0ec8794f7a75fb8537e1a42e24436bcf63298792eb62ff55ee517f38Virustotal results 15.52% Heodo
2018-11-09file-5690921808.docdoc 12b379ac95454c365edf299e087e861fbe8df739dcdb3d82b30dae3c4a201583Virustotal results 15.25% Heodo
2018-11-09FORM-3634478240604804.docdoc 4a455e0a53007d2bc3092d2ed1ba66ca53993255f154100d6e4675822aeff947Virustotal results 17.54% Heodo
2018-11-09form-044068804184.docdoc a4d420b57a6a78d801ec6dc6418c12b85035c500462766e14d3f53da1e0a0158Virustotal results 17.54% Heodo
2018-11-09doc-04376424119461.docdoc 741a12b3a2bc48ae7b429ea0bd15addea3580700b4402707cafe7dcab5d10b8bVirustotal results 44.07% Heodo
2018-11-09form-47038296011.docdoc cdc79aef87d547d7797c8f1950754c7943dc6da4d91604a1e43cb7f32346be73Virustotal results 39.66% Heodo
2018-11-09FILE-5964539384501.docdoc 44bcdc56cd842e5375efc46de3024992c8b06cfb0cfaa661d898f2ee869b821bVirustotal results 37.93% Heodo
2018-11-09eFILE-2264841642948478.docdoc 003591243133d77d308b2aeabaa396dbb8287c60fecf6a7645771e10317d9e5fVirustotal results 38.98% Heodo
2018-11-09doc-300414160323600.docdoc c9f588732f8250f3640df3a5b1dd41aba6847c56718f425856a289b0680bd10cn/a Heodo
2018-11-09file-3273734565209849.docdoc eee7617113d4a7d6efd12c71027618c908f47aa4e4e96b19f4c1805c166fe876Virustotal results 36.21% Heodo
2018-11-08eForm-09689442261891.docdoc 5180c6e94e4132bd1d7c9f7697e00dc17abc7f480bf60ff75c704b714cc3fd7bVirustotal results 43.86% Heodo
2018-11-08eFILE-8389199261.docdoc 7ce6dcf9a399877d416926ac2605fbe901c555d803d5f13253753ef43cfb0817Virustotal results 38.98% 
2018-11-08Untitled-6890587649694417.docdoc e2572648abd3d970d1c2fb7c534913887f1d912f880c20281ca02e853fee129fn/a Heodo
2018-11-08DOC-825644952303317.docdoc 57a7aa7b7a7c7092296f38d964ba38b1405a2022240344a139cf7333bc87af29Virustotal results 32.20% 
2018-11-08Untitled-6410677361143.docdoc df293e00369843ec93a81cf8f96d41a86438bb7a1920b3e347de90a904e8a377Virustotal results 31.03% Heodo
2018-11-08doc-44719645855.docdoc a7e80c448efb6e22d4bbeed42add330ac4d581b42f07d5ccce9073b7298faa27Virustotal results 23.73% Heodo
2018-11-08FORM-18198971373.docdoc f5157bb10f4869655706640c47f5dedd2a97a8ffd49284fff261427521f66bebVirustotal results 22.41% Heodo