URLhaus Database

You are currently viewing the URLhaus database entry for https://investesteinviitor.ro/wp-content/plugins/wp-roilbask/includes/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1991653
URL: https://investesteinviitor.ro/wp-content/plugins/wp-roilbask/includes/
URL Status:Offline
Host: investesteinviitor.ro
Date added:2022-01-20 07:27:09 UTC
Last online:2022-01-20 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 07:28:24 UTC to abuse{at}mxhost[dot]ro)
Takedown time:5 hours, 31 minutes Good (down since 2022-01-20 12:59:27 UTC)
Tags:bazaloader link BazarLoader xll

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20FF-1642682875.xlldll 75cdb51337ba20c2f53bc8dac34e55678cc01b7698550ba91aaa3ce667af32c0Virustotal results 50.00%BazaLoader
2022-01-20FF-1642681793.xlldll 488453b2c3d9e532d42bcb634b9817cb02b5fbf3bdbb4d12f24abca359e44089Virustotal results 52.24%BazaLoader
2022-01-20FF-1642679413.xlldll b31cdc9d1f82f0e85faedf8a95cddcfb94ea68db5c9a496a4365db19b7272380Virustotal results 47.76%BazaLoader
2022-01-20FF-1642678201.xlldll 59136a8738af5783756405f46526e99f705dd94a14dd2629de96880814dacc0cVirustotal results 33.85% BazaLoader
2022-01-20FF-1642677406.xlldll d3dbd89bf43c2ade8f0c590ab831f5a3b200bb5bf370a13450523ef9f094437fVirustotal results 21.88%BazaLoader
2022-01-20FF-1642676327.xlldll 4db56cc519b8fe92f608a30bf32477b62c1f154de183e7f075bb4cf68e918a83Virustotal results 26.87% BazaLoader
2022-01-20FF-1642675229.xlldll d6c5958b3428b877f04dbfe926d80823e014e182b2cda18c0b0e9f2fde835d44Virustotal results 55.22%BazaLoader
2022-01-20FF-1642674467.xlldll f983a109d3d2856794352c36289e6f34f0f55420acfdc196ec9c75095eb79c90Virustotal results 43.94% BazaLoader
2022-01-20FF-1642674038.xlldll 4f5fdd31a9968ef180ac139cd711f49708ee61c0959d0507d65ea29c90033606Virustotal results 41.79% BazaLoader
2022-01-20FF-1642673055.xlldll 2a44ed0a9fda586147fb82a9927090f745e68887712a29d34e4bb1c52a83fba3Virustotal results 25.00%BazaLoader
2022-01-20FF-1642671078.xlldll d5c03179945956647ebd5c1481506cec6cd412bc624872942bbf5f7082536b06Virustotal results 50.00% BazaLoader
2022-01-20FF-1642670066.xlldll 113fa9ae34480ab1f6b091d8928b9716a4e7dffeb3c9c47129ed249af762b47aVirustotal results 46.15% BazaLoader
2022-01-20FF-1642668872.xlldll 3d96364b05eeca8c8e82542c15127c5c648177560e738afcd6160c22a5a4408cVirustotal results 49.23%BazaLoader
2022-01-20FF-1642668376.xlldll 628430a43571477dd00085cdcdaa9a834e030cb80e39ae19b6a107c1f904e2cfVirustotal results 45.31% BazaLoader
2022-01-20FF-1642666137.xlldll f788a8ef14ef471ca30ba366c02b440912db3a113941edc77c1da9cd7b03c513Virustotal results 24.62% BazaLoader
2022-01-20FF-1642665009.xlldll 9bfe3e664dea6ec4c143d6beb35b7cef737163ee64f78e06e4d779859c046138Virustotal results 19.70%BazaLoader
2022-01-20FF-1642663992.xlldll 2741d6da882c151334cb7777b2f8bf26f8b0e197d244f1aa86570b040f334a76Virustotal results 24.24% BazaLoader
2022-01-20FF-1642663624.xlldll 2c2070acd612d96b786e7f8e5ace1fa0965649d4da600936b9f99bf79e331a72Virustotal results 48.53%BazaLoader