URLhaus Database

You are currently viewing the URLhaus database entry for https://treeqpower.com/wp-content/plugins/wp-roilbask/includes/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1980722
URL: https://treeqpower.com/wp-content/plugins/wp-roilbask/includes/
URL Status:Offline
Host: treeqpower.com
Date added:2022-01-16 07:01:04 UTC
Last online:2022-01-20 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 16:38:07 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 3 hours, 40 minutes Poor (down since 2022-01-20 20:18:27 UTC)
Tags:bazaloader link IcedID link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20DH-1642697081.xlldll a9f6712e7cf49bddcbdef715d13768157f94252be28bd74331a9ff963401137cVirustotal results 52.24% BazaLoader
2022-01-20DH-1642684415.xlldll cde9da874805fce066203681f88254cb84d6be7d77b3f0794140decc1e1448eaVirustotal results 51.56%BazaLoader
2022-01-20DH-1642664632.xlldll 2a44ed0a9fda586147fb82a9927090f745e68887712a29d34e4bb1c52a83fba3Virustotal results 25.00%BazaLoader
2022-01-20DH-1642661404.xlldll b31cdc9d1f82f0e85faedf8a95cddcfb94ea68db5c9a496a4365db19b7272380Virustotal results 20.31%BazaLoader
2022-01-20DH-1642657361.xlldll 79cd208d8f4f4720ac7f85e0c3dabc8715dde7ce28e114d1bfd7372f30c10460Virustotal results 39.39% BazaLoader
2022-01-19DH-1642634006.xlldll ad5f4db4dad54f1c69a36a826311d782671ab5e16af827e17920c8180ec28a2eVirustotal results 41.79% BazaLoader
2022-01-19DH-1642630551.xlldll b9161245a81bdee1f12e09a4a66abb8ec219f10a4fbfa2023dcf2ca4a2ab7114Virustotal results 20.00% BazaLoader
2022-01-19DH-1642628905.xlldll 9f99abf0edf0c585155192ef48ca7c3eaa1a479f594ce2ca6406c92f02e1e7feVirustotal results 24.24% BazaLoader
2022-01-19DH-1642621006.xlldll 113fa9ae34480ab1f6b091d8928b9716a4e7dffeb3c9c47129ed249af762b47aVirustotal results 21.54% BazaLoader
2022-01-19DH-1642609860.xlldll 4f5fdd31a9968ef180ac139cd711f49708ee61c0959d0507d65ea29c90033606Virustotal results 19.64% BazaLoader
2022-01-19DH-1642596238.xlldll 56d8a969497fe0cf90aa6e71c8f7c1a2e76b621d0b18876db8e3ca198a7b4350Virustotal results 23.33% BazaLoader
2022-01-19DH-1642594441.xlldll 09f0d56342e53b1af01eceb399c3f0bde5e61ff654d9117a57868466750e2e93Virustotal results 22.73%BazaLoader
2022-01-19DH-1642585466.xlldll 092d57e94574cc3a9afa80daf5b3cb26160e4e4a55df6e48cbb4e314cfe6f509Virustotal results 24.24% BazaLoader
2022-01-19DH-1642581867.xlldll 2741d6da882c151334cb7777b2f8bf26f8b0e197d244f1aa86570b040f334a76Virustotal results 24.24% BazaLoader
2022-01-19DH-1642581150.xlldll b2e7408b9eb3af0bb7c4267432fa08e92fd335ddc72a69acbab123a7d919fb44Virustotal results 22.39%BazaLoader
2022-01-19DH-1642577569.xlldll 9bfe3e664dea6ec4c143d6beb35b7cef737163ee64f78e06e4d779859c046138Virustotal results 19.70%BazaLoader
2022-01-19DH-1642575753.xlldll 4507c736a5aa8756e4ae1f5a43f16fffbf1f8536cde0f450eb2fb8e9edf68142Virustotal results 20.31% BazaLoader
2022-01-19DH-1642570006.xlldll f7a45008c19652c6e48896a7b5abec6c33baff2f663f72457e4efac3e95c48e8Virustotal results 21.21%BazaLoader
2022-01-19DH-1642566024.xlldll 08bf0258a2a82e0ad674a14bcbbac2d84a61cbcb4b172d795ec128eb79831adbVirustotal results 20.31% BazaLoader
2022-01-19DH-1642565097.xlldll fa938c8e0833e3d8a642ab29cb8ecfde8d1ef574837d41a7e4a7c1676ec91531Virustotal results 22.39% BazaLoader
2022-01-19DH-1642564361.xlldll 59136a8738af5783756405f46526e99f705dd94a14dd2629de96880814dacc0cVirustotal results 33.85% BazaLoader
2022-01-19DH-1642563035.xlldll d3dbd89bf43c2ade8f0c590ab831f5a3b200bb5bf370a13450523ef9f094437fVirustotal results 21.88%BazaLoader
2022-01-19DH-1642560516.xlldll a19a61482e4b0b342546fdc14c13f206569e47b6c6ae310136cfd54bdc5b32d8Virustotal results 20.00% BazaLoader
2022-01-19DH-1642559258.xlldll 564ff55dbe619258820e95835d623e037c2daa146c81eb257f7c88ef28f76578Virustotal results 21.31%BazaLoader
2022-01-19DH-1642555645.xlldll 465f6c30e884e9422573f39388e9aff5709c40301baf83369bffac32a797bb4dVirustotal results 20.00% BazaLoader
2022-01-19DH-1642554376.xlldll 18f5ade40bc5441aa11d03672f5a08e0b05e3fdeca5f2903a565ca7632d9e537Virustotal results 32.31% BazaLoader
2022-01-19DH-1642551905.xlldll a134c216fa5bdd844aa6c620365776754d618280a7982aa11b81a11f0bbca307Virustotal results 22.58%BazaLoader
2022-01-19DH-1642551157.xlldll 7e2a361d904e56e56ebdc4c4439e77f63246ae4276f573ad5b5427a0658fc5a3Virustotal results 22.73%BazaLoader
2022-01-18DH-1642548873.xlldll 7912ecf58bf36144f792f5fb357c4194229b1e3728d9852c4376fa297ddaad5fVirustotal results 19.40% BazaLoader
2022-01-18DH-1642548503.xlldll e397e69d94adae69848267c77b54d3599d27f95de11631020b1348b087fcab3bVirustotal results 18.46%BazaLoader
2022-01-18DH-1642546749.xlldll f788a8ef14ef471ca30ba366c02b440912db3a113941edc77c1da9cd7b03c513Virustotal results 24.62% BazaLoader
2022-01-18DH-1642545587.xlldll 75cdb51337ba20c2f53bc8dac34e55678cc01b7698550ba91aaa3ce667af32c0Virustotal results 20.00%BazaLoader
2022-01-18DH-1642544737.xlldll f983a109d3d2856794352c36289e6f34f0f55420acfdc196ec9c75095eb79c90Virustotal results 19.70% BazaLoader
2022-01-18DH-1642543113.xlldll 628430a43571477dd00085cdcdaa9a834e030cb80e39ae19b6a107c1f904e2cfVirustotal results 20.97% BazaLoader
2022-01-18DH-1642540226.xlldll 4db56cc519b8fe92f608a30bf32477b62c1f154de183e7f075bb4cf68e918a83Virustotal results 26.87% BazaLoader
2022-01-18DH-1642539639.xlldll 74111ea2672178a41bb598c8d4239790c37ce0be77ae2f38106f258fd89a38c0Virustotal results 23.08%BazaLoader
2022-01-18DH-1642536953.xlldll d5c03179945956647ebd5c1481506cec6cd412bc624872942bbf5f7082536b06Virustotal results 23.08% BazaLoader
2022-01-18DH-1642534069.xlldll 7d27d8e926562f49922248582238865036fbce5d84fc42cf02ed8fcac1a4074dVirustotal results 22.58%BazaLoader
2022-01-18DH-1642532715.xlldll 52db9c20a7e362af2fd93800154e761a7fbc7253b9c97d77ec2df6c6e691e0c2Virustotal results 26.98%BazaLoader
2022-01-18DH-1642532282.xlldll 964e1ff84b5c231a5176e2e4425d1e8b9186f0b62c02d492505872d48f6dd58bVirustotal results 24.24%BazaLoader
2022-01-18DH-1642531337.xlldll 2045ecc425209bfc5e090d868856afe74cf0cb13dc63f8a00b656aac3fe438eaVirustotal results 21.21% BazaLoader
2022-01-18DH-1642530456.xlldll 488453b2c3d9e532d42bcb634b9817cb02b5fbf3bdbb4d12f24abca359e44089Virustotal results 20.00%BazaLoader
2022-01-18DH-1642529308.xlldll 3d96364b05eeca8c8e82542c15127c5c648177560e738afcd6160c22a5a4408cVirustotal results 20.00%BazaLoader
2022-01-18DH-1642528399.xlldll 2c2070acd612d96b786e7f8e5ace1fa0965649d4da600936b9f99bf79e331a72Virustotal results 26.56%BazaLoader
2022-01-18DH-1642527692.xlldll d6c5958b3428b877f04dbfe926d80823e014e182b2cda18c0b0e9f2fde835d44Virustotal results 23.44%BazaLoader
2022-01-18DH-1642526905.xlldll 03396b2ed677c8afc58f2ce403417e56df85027468621f42ac416a38baa7bc63Virustotal results 20.00% BazaLoader
2022-01-18DH-1642526444.xlldll 3e4533d0e092a0a8c35ea248153062fe54e1a38a4aea9b627de619ad53fe90b3Virustotal results 21.88%BazaLoader
2022-01-18DH-1642525296.xlldll a9040dea33ad6d284d1302e069d31c3b08c3d83de3681dd0557ced13781ca391Virustotal results 24.62% BazaLoader
2022-01-18DH-1642524350.xlldll 7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89Virustotal results 20.00% BazaLoader
2022-01-18DH-1642523851.xlldll a2e85069fc46ebd9d42f5032342656337b40583c3f94f82f653e17dd5bae7f5fVirustotal results 23.08%BazaLoader