URLhaus Database

You are currently viewing the URLhaus database entry for http://kizitox.cf/bobbyzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1880065
URL: http://kizitox.cf/bobbyzx.exe
URL Status:Offline
Host: kizitox.cf
Date added:2021-12-13 10:41:10 UTC
Last online:2022-01-11 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-07 21:34:31 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 0 days, 7 hours, 56 minutes Bad (down since 2022-01-12 18:40:14 UTC)
Tags:AgentTesla link exe Formbook link OskiStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-31n/aexe 6df77c0f8991ed1bdd9a4a317e54351362037de7ee9d8b3ab978ae0a167c1e36n/aAgentTesla
2021-12-23n/aexe 3e07bbefb8a7c7c8b5c46c854eaa422fe047cd22d6c2e96af1b1a88fb78854b0n/aFormbook
2021-12-22n/aexe 33a271b57993a4279618294783f95d3634d0358b5030ea48cf9896475e3d8546Virustotal results 27.94%OskiStealer
2021-12-21n/aexe c80813f3b441b2db332392c2c2665c5f7ed0a02f5c8b65d9f200cedc6efcec28n/a 
2021-12-21n/aexe 8d195b653dc6e3a24027211193dc844da5ed5448532873aebadf3b75e722f42bn/a 
2021-12-20n/aexe 15aeb1edef0fa34d88b0cae99767b604b90138173b024bb4512979b22cae9287n/aFormbook
2021-12-20n/aexe 6a7753dba591a0f953c07a4e13ef1682c3839bcc380545a647da6e24bef41786n/aFormbook
2021-12-20n/aexe 125c9498bdcd38fb36d35e3eb32f45ede843e53eeb57e973255cf11d66318210n/aFormbook
2021-12-13n/aexe 947e0314a5c24952596b1a6f8455e10c642ad0d3dc88a57bcef1ecbdf69d418bn/aFormbook