URLhaus Database

You are currently viewing the URLhaus database entry for http://nkai.xyz/CDsupport.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2232785
URL: http://nkai.xyz/CDsupport.exe
URL Status:Offline
Host: nkai.xyz
Date added:2022-06-10 09:22:04 UTC
Last online:2022-06-12 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2022-06-12 05:20:06 UTC to abuse{at}stark-industries[dot]solutions)
Takedown time:2 days, 5 hours, 4 minutes Poor (down since 2022-06-12 14:27:50 UTC)
Tags:exe XFilesStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-12n/aexe 3e092962b8b5793208b6268d616bd3ca63c64de3c6bf61fc63d1d4df3e69c014n/aXFilesStealer
2022-06-11n/aexe 91ee7495202ee70917b54a58444f844455513ed4f743721a745abb6dd99e2315n/a XFilesStealer
2022-06-11n/aexe 11ae2e344df90b0498ef2a129063c02b47e6df3bf91ed1b3e6ea1cc30335f7c7n/a XFilesStealer
2022-06-10n/aexe f1891e8658060a83c1492303243e7176798fedb3ad23ef4235cb0a726dd36addn/a XFilesStealer
2022-06-10n/aexe 1887989d168e18606bf175ddb1a83e6ca5af7eb2bcbd60be37e729ecd0ab8bb0n/aXFilesStealer
2022-06-10n/aexe f5bb4fe0d4f2f4aaf604140cb41dbca8c8b7baee8229998a956be12ce5d01408n/aXFilesStealer