URLhaus Database

You are currently viewing the URLhaus database entry for https://sakshamsanchar.org/wp-content/plugins/wp-roilbask/includes/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1987730
URL: https://sakshamsanchar.org/wp-content/plugins/wp-roilbask/includes/
URL Status:Offline
Host: sakshamsanchar.org
Date added:2022-01-18 23:11:09 UTC
Last online:2022-01-19 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 23:12:15 UTC to abuse{at}cloudflare[dot]com)
Takedown time:5 hours, 41 minutes Good (down since 2022-01-19 04:53:51 UTC)
Tags:bazaloader link BazarLoader IcedID link xll

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-19FF-1642566666.xlldll a19a61482e4b0b342546fdc14c13f206569e47b6c6ae310136cfd54bdc5b32d8Virustotal results 20.00% BazaLoader
2022-01-19FF-1642564145.xlldll f788a8ef14ef471ca30ba366c02b440912db3a113941edc77c1da9cd7b03c513Virustotal results 24.62% BazaLoader
2022-01-19FF-1642562487.xlldll 4507c736a5aa8756e4ae1f5a43f16fffbf1f8536cde0f450eb2fb8e9edf68142Virustotal results 20.31% BazaLoader
2022-01-19FF-1642561456.xlldll ad5f4db4dad54f1c69a36a826311d782671ab5e16af827e17920c8180ec28a2eVirustotal results 20.00% BazaLoader
2022-01-19FF-1642560359.xlldll a9040dea33ad6d284d1302e069d31c3b08c3d83de3681dd0557ced13781ca391Virustotal results 24.62% BazaLoader
2022-01-19FF-1642558366.xlldll 7d27d8e926562f49922248582238865036fbce5d84fc42cf02ed8fcac1a4074dVirustotal results 22.58%BazaLoader
2022-01-19FF-1642557609.xlldll a134c216fa5bdd844aa6c620365776754d618280a7982aa11b81a11f0bbca307Virustotal results 34.85%BazaLoader
2022-01-19FF-1642554035.xlldll 79cd208d8f4f4720ac7f85e0c3dabc8715dde7ce28e114d1bfd7372f30c10460Virustotal results 17.65% BazaLoader
2022-01-19FF-1642553381.xlldll a9f6712e7cf49bddcbdef715d13768157f94252be28bd74331a9ff963401137cVirustotal results 20.00% BazaLoader
2022-01-19FF-1642551669.xlldll e397e69d94adae69848267c77b54d3599d27f95de11631020b1348b087fcab3bVirustotal results 18.46%BazaLoader
2022-01-19FF-1642550509.xlldll fa938c8e0833e3d8a642ab29cb8ecfde8d1ef574837d41a7e4a7c1676ec91531Virustotal results 22.39% BazaLoader
2022-01-18FF-1642549736.xlldll 03396b2ed677c8afc58f2ce403417e56df85027468621f42ac416a38baa7bc63Virustotal results 20.00% BazaLoader
2022-01-18FF-1642549229.xlldll b9161245a81bdee1f12e09a4a66abb8ec219f10a4fbfa2023dcf2ca4a2ab7114Virustotal results 20.00% BazaLoader
2022-01-18FF-1642547813.xlldll 488453b2c3d9e532d42bcb634b9817cb02b5fbf3bdbb4d12f24abca359e44089Virustotal results 20.00%BazaLoader
2022-01-18FF-1642547466.xlldll 74111ea2672178a41bb598c8d4239790c37ce0be77ae2f38106f258fd89a38c0Virustotal results 37.31%BazaLoader