URLhaus Database

You are currently viewing the URLhaus database entry for http://kizitox.cf/kdotzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1901331
URL: http://kizitox.cf/kdotzx.exe
URL Status:Offline
Host: kizitox.cf
Date added:2021-12-20 09:18:09 UTC
Last online:2022-02-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-02-23 06:52:07 UTC to joost[dot]zuurbier{at}verotel[dot]com)
Takedown time:2 months, 4 days, 22 hours, 21 minutes Bad (down since 2022-02-23 07:42:14 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-19n/aexe e165fc3e8b1e46c7bbe31b7e533ad07cb086fd453afed08cfa1dad73686dc2fdn/aAgentTesla
2022-01-14n/aexe 885959e47acb379cf2b91830300be880669d822ef1433dfaa8d121e078135cfbn/a AgentTesla
2022-01-13n/aexe 86f05b46beceee5220439b9b874e58ff20fc54526c2b7b494797be7c50078125n/aAgentTesla
2022-01-12n/aexe ccd3b1025026f005eab390a02815e3689f879ea7ad985f5aa760b208d4f27318n/aAgentTesla
2022-01-12n/aexe 074df4d5efd64f143ab55fa20e5133a62dee4cf95a4622ebbb1aa805837add24n/aAgentTesla
2021-12-21n/aexe 7191f7c8d6fecac1daa7573f1985865a79edaaf1c1e81ff630c4d4768db306efn/a 
2021-12-20n/aexe 279ce0d724916bb8c329d62f1e010fa76935b6f10b188fa9d18788006c4d6bf4n/a 
2021-12-20n/aexe 1d0faaafa06db1640ed6d2740c6e89167bed375422863549d8974c28b62670e6Virustotal results 31.82%AgentTesla