URLhaus Database

You are currently viewing the URLhaus database entry for https://kiff.store/links/uploads/PlsWnEU2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1493684
URL: https://kiff.store/links/uploads/PlsWnEU2.exe
URL Status:Offline
Host: kiff.store
Date added:2021-07-30 21:20:12 UTC
Last online:2021-10-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-08 06:42:25 UTC to abuse{at}greenfloid[dot]com)
Takedown time:2 months, 9 days, 9 hours, 59 minutes Bad (down since 2021-10-08 07:20:55 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-07n/aexe 2553df4a9377b9130be7ac754e3a562e12ed518958574fcfe2cf979925e3a4c4n/a RedLineStealer
2021-10-05n/aexe 4e3aa3a3bc4a924d39440b7c7db4da2b2896d925e3114781532abb366e488819n/a RedLineStealer
2021-10-04n/aexe 9a636d4ed2ff7b4e0c54ebc9e395b825512a5734744ac3c556cee74295cf692fn/a RedLineStealer
2021-10-02n/aexe 0b67e5f12c073b9fcd46323a98226372df0b6c2b5d85d76deb5f6986192ccd94n/a RedLineStealer
2021-10-01n/aexe ebdf4584996176cff09f646ee75bb3abfb21ec6b08d56a3bbe2166c162c30801n/a RedLineStealer
2021-09-29n/aexe 7e23f8ef88c8dcbf3836e97659798d9874ff0ab852366547ddd88369351645d9n/a RedLineStealer
2021-09-27n/aexe da1eee55cafa2885d83fe8f3b78e184a869e67976e344c81d4f5eb3d675371e1n/a RedLineStealer
2021-09-27n/aexe 5327f332ce8fb1393180d26229a2166c1182a3e1b3d3b29c5f8b753f26fa5a07n/aRedLineStealer
2021-09-25n/aexe 78efd6901608ccf794a8fca6f33147aafd874fcab46a23aa09becb2dbf159fd2n/a RedLineStealer
2021-09-21n/aexe 99f6d5723f93ac9689ea1f428b9a090b55f068ecdebcfdff854bef0dbd26db6dVirustotal results 31.82%RedLineStealer
2021-09-15n/aexe 8501ecc1e81ea29bd1be1dde7523c712c1a5ce63479346bdd1750a7aa52838a0n/a 
2021-09-14n/aexe 6a7fe1fbf54901dcdad6368d5ba172c225a23101bfe7725c2e5a40cc3a66d5f0n/a RedLineStealer
2021-09-13n/aexe 9e4f1265989f3ef1ea4ea6ece2e0d45bf22e8d13d14c41f184eee9dc66f10cd2n/a RedLineStealer
2021-09-12n/aexe 154608f407e2e4dbf358167360b83b6ec98774e4684628781ce1f5af5e825fb0n/a RedLineStealer
2021-09-11n/aexe dcf02bc210374bf568da665cfa4ba4699365274bfe3cab05764bf5ed0704cd63n/a RedLineStealer
2021-09-10n/aexe b612f7e8119f6fdf15fc92a4cd62ec6eca06b27cbbcd609bdae0c1a5ddd6d436n/a RedLineStealer
2021-09-10n/aexe 5dbea37bc85ae4e19f2ac5dff110664e2a4383c9a483d9478a2dd5ffda06c802Virustotal results 39.13% RedLineStealer
2021-07-30n/aexe 035746e04151155cd17968d895bc7ec8d03f2b50c26e569102999d39bd1dd179Virustotal results 18.84%RedLineStealer