URLhaus Database

You are currently viewing the URLhaus database entry for https://kiff.ltd/links/uploads/IwtblEU2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2017879
URL: https://kiff.ltd/links/uploads/IwtblEU2.exe
URL Status:Offline
Host: kiff.ltd
Date added:2022-01-31 07:42:14 UTC
Last online:2022-02-17 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-01-31 07:44:04 UTC to abuse{at}greenfloid[dot]com)
Takedown time:17 days, 4 hours, 19 minutes Bad (down since 2022-02-17 12:04:01 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-02n/aexe 7f72ecd51295dc108957c937e34ac63b9043c30afb2eb0323a776f1423d0eb94n/a 
2022-02-02n/aexe abd054e7a6a48ac8a33ffa9fab4814d0c68149f5a5eea1b0a68e84d2057811d6n/aRedLineStealer
2022-02-01n/aexe faec9f2bb4da32ed322a8d98e634997ba23d2b28aa64a2efe7d49d6bb2f15467n/aRedLineStealer
2022-01-31n/aexe b4f2b45e48cf433196a2911b98290d06c64ec17b6f69d88e26adc29628494ffbn/a RedLineStealer
2022-01-31n/aexe e708823ea6f27372ae9ff3d1b1c12f02ccb29bdbb02112906c560d0806b2746cn/a RedLineStealer
2022-01-31n/aexe a9512d7f86393138f7c628ea275242542d3aeab0616979bff5de178841d22024Virustotal results 25.76%RedLineStealer