URLhaus Database

You are currently viewing the URLhaus database entry for https://www.royalcityplumbing.ca/wp-content/plugins/wp-roilbask/includes/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1970242
URL: https://www.royalcityplumbing.ca/wp-content/plugins/wp-roilbask/includes/
URL Status:Offline
Host: www.royalcityplumbing.ca
Date added:2022-01-12 09:05:08 UTC
Last online:2022-01-13 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-01-12 09:07:21 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:23 hours, 23 minutes Good (down since 2022-01-13 08:30:39 UTC)
Tags:IcedID link wp-roilbask xll

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-13DH-1642054045.xlldll 36eea2780c6330a824f03fde03e1c465c19d1706909af8ab1da60acb3b7f02b4Virustotal results 0.00% IcedID
2022-01-13DH-1642052263.xlldll 6062599bb13ef036a42185ad9d1e2f58665f29d665626ce95571c49e0107f5dbVirustotal results 0.00% IcedID
2022-01-13DH-1642051850.xlldll 31ea2c96fb914d5d932a3176db0400ffbaac1af2d5b89d4f5bb58380d5cb7fa9Virustotal results 0.00% IcedID
2022-01-13DH-1642050125.xlldll 5a5bcd7586232234b26c06e0a0bce8ab5e4fcf32379c4f1529fa4f3797e4ea95Virustotal results 0.00% IcedID
2022-01-13DH-1642046186.xlldll 149e1550810651ae047350af9dd52f2875b483fa7cc2b5a641d68678317d5e97Virustotal results 0.00% IcedID
2022-01-13DH-1642043163.xlldll 3160725ecb2e49e109db6db96cb5dd7c537fe5ef8198bdcae2e55a9aa5de3384Virustotal results 0.00% IcedID
2022-01-13DH-1642040893.xlldll a7d8021fc936f12b656c03b768cb00c53888073cd548b179a81529b9e36892f0Virustotal results 0.00% IcedID
2022-01-13DH-1642038888.xlldll b6e82ee1beaffc29641bedf570c5a2704f76c1da1f0ac9f97337075e6c8ed75aVirustotal results 2.99% IcedID
2022-01-13DH-1642037038.xlldll 415abfb2785209977e7293d58e6ec29345a1be9dc343ae69f17e96c5346f9fe7Virustotal results 0.00%IcedID
2022-01-13DH-1642035995.xlldll ad095615f5b450c9f7ca1b115587c9708739bae844b819663248799f4a927aceVirustotal results 4.55%IcedID
2022-01-13DH-1642035118.xlldll d1e61f9b080e3b6892df3660c346870ec62ce7627437bc666d7e369e215f5f43Virustotal results 0.00% IcedID
2022-01-13DH-1642033886.xlldll 1dfc17329674661fef45cc7b5b81891505821f454cdec5791370ba2cca1832f3Virustotal results 0.00% IcedID
2022-01-12DH-1642028184.xlldll cf69a7a2b9beb8ae178df59e31393bc33ba69f9ec15b5cced248ba459f2caefcVirustotal results 2.99% IcedID
2022-01-12DH-1642027495.xlldll 97f67fca98471d15b171917f1b24e9bc85d4ca6e94b57985235f611c15637bbdVirustotal results 0.00% IcedID
2022-01-12DH-1642023569.xlldll 105047a088c424564285c660467e7d848743d0d932918d060b937e85e9f7ddd0Virustotal results 0.00% IcedID
2022-01-12DH-1642020519.xlldll e4fdc8b6743a24bcb75957fc1c2591dd552637e33184affe233f2ec7aa694225Virustotal results 0.00%IcedID
2022-01-12DH-1642019456.xlldll 718c54d1146a1d4a10fa7791295332e1bc18b906cbf5ee56e1f8a34b238b4cf0Virustotal results 2.99% IcedID
2022-01-12DH-1642015532.xlldll 386a6b2542e3d43404d66edb56283b4bbb8b54f0c67812ac8ae272601774e676Virustotal results 0.00% IcedID
2022-01-12DH-1642014329.xlldll a670f3ada5b3b1ecbe3e5deca339cf032fa84d60e3ca18be4ba31f0aac0046b6Virustotal results 0.00% IcedID
2022-01-12DH-1642013794.xlldll 1a47ab49a5341a3cfc40bd7a64dea46cb8cad224314a51410e7ad56bb6bb93b0n/a IcedID
2022-01-12DH-1642012639.xlldll c32f6612f756900f22fe617bb11d8ac5793851efdc29bc38b129cf6516a841fbVirustotal results 0.00% IcedID
2022-01-12DH-1642011241.xlldll cbcb0c99f879bbedf38347b63fa62c480f12580e5cb95a4a357bbef602d96e61Virustotal results 0.00%IcedID
2022-01-12DH-1642008176.xlldll 25cccdb32c59c9f617d5a40b1c0f8fc39760ae3fc2a68bc3c3708c02a0a7389dn/aIcedID
2022-01-12DH-1642007005.xlldll 93680a56efaa95e69cf26ec2a98c2de094425654db8a6c3b91f2fabc95d5cc21n/a IcedID
2022-01-12DH-1642006034.xlldll e81beba107b603de192702d9ce123e5bd73260e3914f4dc291fcb9725e5ef1bcVirustotal results 2.99% IcedID
2022-01-12DH-1642004306.xlldll 09f61d519da2be5534a3089c1a1a9ddf53e66add5cec3812514f936301728142n/a IcedID
2022-01-12DH-1642003172.xlldll d61b19edd293a0691527f40fb136511022d2c106bac5b770f9aedcea445c70adn/a IcedID
2022-01-12DH-1642002169.xlldll 6f7dfdabd97519cfe18e64f8e7d8663c7ad6d7422ba5ed09b473ebe290848e5dn/a IcedID
2022-01-12DH-1642000902.xlldll 6cb4bd982b2cd8453206293fef87d30123766482cedcf17c53957810af96cdb6n/a IcedID
2022-01-12DH-1641999157.xlldll 99b64250b1cf93df611e3d4dbc6c80c102bb54d31495f1d95ffadb80a24a1c92Virustotal results 0.00% IcedID
2022-01-12DH-1641998153.xlldll f25457885aa82374e3c250c2f89cb4ea9a4307715551e2c60618f7bd6887d52eVirustotal results 0.00% IcedID
2022-01-12DH-1641996575.xlldll 2775fd1fce482977acac8bf3bf7f8af4ed6c98630497317df49d7843b3a64543Virustotal results 0.00% IcedID
2022-01-12DH-1641994388.xlldll 59ac4760631f394ca1a41bc3dd7b4476fda6dcba1a8811f6190f4bab29a5f5c8Virustotal results 3.03% IcedID
2022-01-12DH-1641993512.xlldll c149e4af0dd0c309c0ae96999eb70fed0583cc318d69f3cccf1809300843ba56Virustotal results 0.00% IcedID
2022-01-12DH-1641991152.xlldll 8e66a80288d6f6ef23e1057309ab41fdfcd670dee1bd2752100488a5fb3e27bfVirustotal results 3.08% IcedID
2022-01-12DH-1641988638.xlldll 95cf4f58f7728d43b7bf60c3686db69cd465efc99609d21b417359dfb7697e3cVirustotal results 3.03% IcedID
2022-01-12DH-1641987481.xlldll c7ab043e746c02b08e2f0f6f1957f6e5e699ddc5d263e6e52004ecb507102217Virustotal results 0.00% IcedID
2022-01-12DH-1641986955.xlldll 5f6d60e0a6d16a8d4f3b3856505e73aa1e4235613e9edb2cea74f567c1583f10Virustotal results 0.00% IcedID
2022-01-12DH-1641985436.xlldll 784a4064eb633ce7eafaec660b3b9c60a20b395a1af516fe1b8bebaf9113380eVirustotal results 0.00% IcedID
2022-01-12DH-1641985167.xlldll 7c0990e56342e75681d975c394faf56cabd13b73f9d08cd158a96fff4fcef4a8Virustotal results 0.00% IcedID
2022-01-12DH-1641982720.xlldll a9bca07c8e766ef6c19373f900834d168b116d325767402670ae5c232f81d46dVirustotal results 0.00% IcedID
2022-01-12DH-1641981803.xlldll 720fd64e0dd6bd4ed89e497069f3fab6c3e582ff689f87a51a8adc4e96970c8eVirustotal results 0.00% IcedID
2022-01-12DH-1641980119.xlldll 1e04ef3ce55c2925e2442a620b377060ee363294c4b1fef6c008ff8d6f874061Virustotal results 0.00% IcedID
2022-01-12DH-1641978305.xlldll 196533380a1caa82bba0cc7362801ed548e21f5fcd41cf041caa311ffd747d04n/a IcedID