URLhaus Database

You are currently viewing the URLhaus database entry for http://redtrack4.com/wp-content/plugins/wp-roilbask/includes/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992491
URL: http://redtrack4.com/wp-content/plugins/wp-roilbask/includes/
URL Status:Offline
Host: redtrack4.com
Date added:2022-01-20 12:16:28 UTC
Last online:2022-01-20 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: im_geeg
Abuse complaint sent (?): Yes (2022-01-20 12:18:20 UTC to noc{at}hostcollective[dot]com)
Takedown time:3 hours, 42 minutes Good (down since 2022-01-20 16:01:01 UTC)
Tags:bazaloader link BazarLoader IcedID link wp-roilbask

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20FF-1642692489.xlldll 7d27d8e926562f49922248582238865036fbce5d84fc42cf02ed8fcac1a4074dVirustotal results 22.58%BazaLoader
2022-01-20FF-1642691528.xlldll b2e7408b9eb3af0bb7c4267432fa08e92fd335ddc72a69acbab123a7d919fb44Virustotal results 22.39%BazaLoader
2022-01-20FF-1642690876.xlldll 9bfe3e664dea6ec4c143d6beb35b7cef737163ee64f78e06e4d779859c046138Virustotal results 19.70%BazaLoader
2022-01-20FF-1642689822.xlldll 03396b2ed677c8afc58f2ce403417e56df85027468621f42ac416a38baa7bc63Virustotal results 20.00% BazaLoader
2022-01-20FF-1642688470.xlldll 18f5ade40bc5441aa11d03672f5a08e0b05e3fdeca5f2903a565ca7632d9e537Virustotal results 32.31% BazaLoader
2022-01-20FF-1642688021.xlldll 7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89Virustotal results 20.00% BazaLoader
2022-01-20FF-1642686629.xlldll 628430a43571477dd00085cdcdaa9a834e030cb80e39ae19b6a107c1f904e2cfVirustotal results 45.31% BazaLoader
2022-01-20FF-1642685662.xlldll e397e69d94adae69848267c77b54d3599d27f95de11631020b1348b087fcab3bVirustotal results 44.78%BazaLoader
2022-01-20FF-1642685125.xlldll d3dbd89bf43c2ade8f0c590ab831f5a3b200bb5bf370a13450523ef9f094437fVirustotal results 21.88%BazaLoader
2022-01-20FF-1642683641.xlldll 2741d6da882c151334cb7777b2f8bf26f8b0e197d244f1aa86570b040f334a76Virustotal results 24.24% BazaLoader
2022-01-20FF-1642683004.xlldll a9f6712e7cf49bddcbdef715d13768157f94252be28bd74331a9ff963401137cVirustotal results 49.25% BazaLoader
2022-01-20FF-1642681839.xlldll d5c03179945956647ebd5c1481506cec6cd412bc624872942bbf5f7082536b06Virustotal results 50.00% BazaLoader
2022-01-20FF-1642680980.xlldll 75cdb51337ba20c2f53bc8dac34e55678cc01b7698550ba91aaa3ce667af32c0Virustotal results 50.00%BazaLoader