URLhaus Database

You are currently viewing the URLhaus database entry for http://kizitox.cf/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1881590
URL: http://kizitox.cf/plugmanzx.exe
URL Status:Offline
Host: kizitox.cf
Date added:2021-12-13 19:11:10 UTC
Last online:2022-01-12 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-07 21:34:31 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 4 days, 10 hours, 21 minutes Bad (down since 2022-01-17 05:36:27 UTC)
Tags:exe Formbook link NanoCore link rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14n/aexe 998746d0f5d0c13df720f0bf3981d652c828ea64d64d2e16736a80123fb534aan/aNanoCore
2022-01-12n/aexe 1fd93f45ddbe62337f2b72e31e6a82880bc0581430abeaebda88ac1f58272210n/aNanoCore
2022-01-11n/aexe 64eb8c47b054d4cff298dff325c44cbedf6d4e42a7c950eab90656b4f384287an/aNanoCore
2021-12-22n/aexe 4f97e52ca46091f7651cfebc671b00a7c8c1abd92e2b532eb141c0266eecb2f0Virustotal results 17.19%NanoCore
2021-12-20n/aexe 5919fe9153a8dde8154efd94fd0df3d858ff8558ae51165c13966f844a6090dfn/aFormbook
2021-12-15n/aexe af603c604b707a9b592b13f0e26160f558785e320af60b8a0baad811cdab9cd2n/aRemcosRAT
2021-12-14n/aexe 5ecfba2425ba981af54ae9c114e07e5408999615185a0fbe60e00a22c29aba15n/aRemcosRAT
2021-12-13n/aexe 1aa2a73ddaf95de7b6bda630197f4f44e7b74e0424916f5c6ce8d0751c205674n/aRemcosRAT