URLhaus Database

You are currently viewing the URLhaus database entry for https://kinkyplaystore.com/rmiu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2648196
URL: https://kinkyplaystore.com/rmiu/
URL Status:Offline
Host: kinkyplaystore.com
Date added:2023-05-31 21:05:14 UTC
Last online:2023-06-01 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-31 21:06:31 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:9 hours, 4 minutes Good (down since 2023-06-01 06:10:37 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-01doc_E540_May_31.zipzip 3248619de4d7f8268bc6fe6bafe3418df027d861a749ac5168cfa0fb04c3ab25Virustotal results 29.03% Quakbot
2023-06-01doc_A238_May_31.zipzip 9250ecee0cc29b5f8f7ed0be744bbb006d5ed349d877095e9cd36c51b3e61c3bVirustotal results 23.73% Quakbot
2023-05-31doc_C972_May_31.zipzip 3f26f0dd4f866a1d500b568fc88716d3429344a4d3098bd9737e3e85c7209b10Virustotal results 18.64% Quakbot
2023-05-31doc_D739_May_31.zipzip 3e202cdc11c26cdbe07e54af390ffadce1a9965f2b0cf50f48258724d1d1790bVirustotal results 25.81% Quakbot
2023-05-31doc_A824_May_31.zipzip 60289159c2c2311791c078276b634b16192e733a2c88097fcdf4e586f8be887aVirustotal results 24.19% Quakbot