URLhaus Database

You are currently viewing the URLhaus database entry for http://sewamobilsolonesia.com/wp-content/plugins/wp-roilbask/includes/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1987740
URL: http://sewamobilsolonesia.com/wp-content/plugins/wp-roilbask/includes/
URL Status:Offline
Host: sewamobilsolonesia.com
Date added:2022-01-18 23:11:15 UTC
Last online:2022-01-19 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-18 23:12:34 UTC to abuse{at}jalanet[dot]co[dot]id)
Takedown time:4 hours, 39 minutes Good (down since 2022-01-19 03:51:53 UTC)
Tags:bazaloader link BazarLoader xll

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-19DH-1642562342.xlldll 4507c736a5aa8756e4ae1f5a43f16fffbf1f8536cde0f450eb2fb8e9edf68142Virustotal results 20.31% BazaLoader
2022-01-19DH-1642561300.xlldll d3dbd89bf43c2ade8f0c590ab831f5a3b200bb5bf370a13450523ef9f094437fVirustotal results 21.88%BazaLoader
2022-01-19DH-1642559454.xlldll 964e1ff84b5c231a5176e2e4425d1e8b9186f0b62c02d492505872d48f6dd58bVirustotal results 24.24%BazaLoader
2022-01-19DH-1642558295.xlldll 2c2070acd612d96b786e7f8e5ace1fa0965649d4da600936b9f99bf79e331a72Virustotal results 35.82%BazaLoader
2022-01-19DH-1642557895.xlldll 7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89Virustotal results 20.00% BazaLoader
2022-01-19DH-1642556668.xlldll 628430a43571477dd00085cdcdaa9a834e030cb80e39ae19b6a107c1f904e2cfVirustotal results 23.88% BazaLoader
2022-01-19DH-1642555699.xlldll ad5f4db4dad54f1c69a36a826311d782671ab5e16af827e17920c8180ec28a2eVirustotal results 20.00% BazaLoader
2022-01-19DH-1642554695.xlldll 9bfe3e664dea6ec4c143d6beb35b7cef737163ee64f78e06e4d779859c046138Virustotal results 19.70%BazaLoader
2022-01-19DH-1642553776.xlldll a9040dea33ad6d284d1302e069d31c3b08c3d83de3681dd0557ced13781ca391Virustotal results 24.62% BazaLoader
2022-01-19DH-1642553268.xlldll b31cdc9d1f82f0e85faedf8a95cddcfb94ea68db5c9a496a4365db19b7272380Virustotal results 20.31%BazaLoader
2022-01-19DH-1642552171.xlldll 488453b2c3d9e532d42bcb634b9817cb02b5fbf3bdbb4d12f24abca359e44089Virustotal results 20.00%BazaLoader
2022-01-19DH-1642551511.xlldll 79cd208d8f4f4720ac7f85e0c3dabc8715dde7ce28e114d1bfd7372f30c10460Virustotal results 17.65% BazaLoader
2022-01-19DH-1642551213.xlldll 09f0d56342e53b1af01eceb399c3f0bde5e61ff654d9117a57868466750e2e93Virustotal results 22.73%BazaLoader
2022-01-18DH-1642550239.xlldll a9f6712e7cf49bddcbdef715d13768157f94252be28bd74331a9ff963401137cVirustotal results 20.00% BazaLoader
2022-01-18DH-1642549201.xlldll 08bf0258a2a82e0ad674a14bcbbac2d84a61cbcb4b172d795ec128eb79831adbVirustotal results 20.31% BazaLoader
2022-01-18DH-1642547854.xlldll 2a44ed0a9fda586147fb82a9927090f745e68887712a29d34e4bb1c52a83fba3Virustotal results 25.00%BazaLoader
2022-01-18DH-1642547468.xlldll f788a8ef14ef471ca30ba366c02b440912db3a113941edc77c1da9cd7b03c513Virustotal results 24.62% BazaLoader