URLhaus Database

You are currently viewing the URLhaus database entry for https://tungphamblog.com/Kolodi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2734926
URL: https://tungphamblog.com/Kolodi.exe
URL Status:Offline
Host: tungphamblog.com
Date added:2023-11-24 04:00:13 UTC
Last online:2024-01-10 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-01-10 18:09:06 UTC to abuse+arin{at}bodis[dot]com)
Takedown time:1 month, 18 days, 9 hours, 8 minutes Bad (down since 2024-01-11 13:09:44 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-28n/aexe 2237206ab4781be0819359540bb08409783ebf853e5df60e4683ff60ea3e7f5cn/a RedLineStealer
2023-11-27n/aexe a719b6410b2e125322b304e54d98ff5273d5e097aafce82f8acadca572d1c522Virustotal results 38.89% RedLineStealer
2023-11-25n/aexe c189f0fb469d1614cabaf2c7ecad116504f2a89da8c51f371dd28571dc45a13cVirustotal results 40.85% RedLineStealer
2023-11-24n/aexe 6afc7d0eea79bfc7721b0299c38c99740b57766a1dee973f8ff7219f3cca9dd7Virustotal results 33.33%RedLineStealer
2023-11-24n/aexe f7a1d39832ffeb8e521d78612d2e509e7bc14d96a98b1db48191f7c23b893cafVirustotal results 36.11%RedLineStealer