URLhaus Database

You are currently viewing the URLhaus database entry for http://cloud55file.cc/load/kythy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3855071
URL: http://cloud55file.cc/load/kythy.exe
URL Status:Offline
Host: cloud55file.cc
Date added:2026-05-29 06:33:21 UTC
Last online:2026-06-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-06-03 05:08:12 UTC to abuse{at}ipbnb[dot]com,admin{at}intezio[dot]net)
Takedown time:6 days, 0 hours, 46 minutes Bad (down since 2026-06-04 13:46:41 UTC)
Tags:ACRStealer exe GhostPulse opendir RemusStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-04kythy.exeexe f2077252daf1b3f1c096e35e3c49132490e063c3f5d8a4bedfdfb83105af2902n/a GhostPulse
2026-06-04kythy.exeexe 8fcea116c84046b1180cdfd1e0224d4ca4c8e068883dbd76b0e0012c4d9a8fa4n/a RemusStealer
2026-06-03kythy.exeexe 661eca6015f9a7189699cdd40a220e4f1aa6f0922fd3a5bbd5843be04d68cb78n/a GhostPulse
2026-06-03kythy.exeexe 78943c97e3016c8e2b1c3659700874673412509ef21d90e4bc9013a59a658489n/a GhostPulse
2026-06-02kythy.exeexe 6a8f7d5378791aecbbcbd8e543f36b639eb14c0ac32c27d7278f3e679c888951n/a GhostPulse
2026-06-02kythy.exeexe 07407c800473645f3b46757bae62c0181707ce4b096aad7cc24a7c6a0631ae38n/a GhostPulse
2026-06-01kythy.exeexe 5c5e737d12640b9ad887f56fce1bf395894ad6dd5171b4a1fdaf6a7d5a731a25n/a GhostPulse
2026-06-01kythy.exeexe 571d5dd37becb36e122e55cbd37e0bc537b664def64ae648cda014d8b264a0d6n/a 
2026-05-31kythy.exeexe 7ac3cbd4a0e8b1457d70b9a916ca18a00862508cdeb98a122bf3d7b5876c5974n/a GhostPulse
2026-05-31kythy.exeexe c4c4b0b8fa4f48e6a30899a3820df6ed65f5a32f3caee01e75ae7e531111d7fan/a 
2026-05-30kythy.exeexe 0b5b5c70f1cbbf7d47318f0a49505d07ef9b86e4c812e39f9ad47210f6ae80aen/a RemusStealer
2026-05-29kythy.exeexe ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10an/aACRStealer