URLhaus Database

You are currently viewing the URLhaus database entry for http://kizitox.cf/kellyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1871135
URL: http://kizitox.cf/kellyzx.exe
URL Status:Offline
Host: kizitox.cf
Date added:2021-12-10 08:42:09 UTC
Last online:2021-12-24 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-12-22 16:55:34 UTC to abuse{at}serverion[dot]com)
Takedown time:24 days, 3 hours, 29 minutes Bad (down since 2022-01-03 12:13:27 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-21n/aexe 8342c52be1753814cb650626781ce53e131355da2cc999c3c7129414e25cf49fn/a 
2021-12-21n/aexe d12e42068327c91345eb301afb04de30069130447e4e3b62e914b131705d4b53n/a 
2021-12-20n/aexe 633ad8beecf7e68a344492aa6722033b10aeb60cdf3ddeb2bc67dfa42efb16afn/aFormbook
2021-12-15n/aexe 754d0c2b1277e1c89a1220f33cdb795900b882bfb5b0fc003b1880e55c4fbec1n/aFormbook
2021-12-14n/aexe 58d05ac8e9716f4322f5d39d676a3415c7f499e99c8fa5d920bbbecdb4a616b7n/aFormbook
2021-12-13n/aexe 55028ddc6704717154ae4a43603da57d1099caee821c64c92722519f00c88e6dn/aFormbook
2021-12-13n/aexe c5c6248caa8d0e035434be7fefacaacdc490b1f763917683db5270cfe7d289aan/aFormbook
2021-12-13n/aexe 0e05f364eea6b843357ec8a4991d1dd52fdf847d2386799d62275742f7787d08n/aFormbook
2021-12-10n/aexe 6be874893cea5091522ea17e86689fbc000b283779e768760b74f05176ba7346n/aFormbook
2021-12-10n/aexe d211ed2bfcc045537d4c74ad6e630cbc455a9ff1d76c51470962883398f3e2bfVirustotal results 19.40%Formbook