URLhaus Database

You are currently viewing the URLhaus database entry for http://cloud55file.cc/load/kythy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3855071
URL: http://cloud55file.cc/load/kythy.exe
URL Status:Offline
Host: cloud55file.cc
Date added:2026-05-29 06:33:21 UTC
Last online:2026-06-01 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Phishing domain
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-29 13:00:21 UTC to abuse{at}intezio[dot]net)
Takedown time:2 days, 19 hours, 11 minutes Poor (down since 2026-06-01 08:11:32 UTC)
Tags:ACRStealer exe GhostPulse opendir RemusStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-31kythy.exeexe 7ac3cbd4a0e8b1457d70b9a916ca18a00862508cdeb98a122bf3d7b5876c5974n/a GhostPulse
2026-05-31kythy.exeexe c4c4b0b8fa4f48e6a30899a3820df6ed65f5a32f3caee01e75ae7e531111d7fan/a 
2026-05-30kythy.exeexe 0b5b5c70f1cbbf7d47318f0a49505d07ef9b86e4c812e39f9ad47210f6ae80aen/a RemusStealer
2026-05-29kythy.exeexe ae3ee04fded710b733a8eba2eb8e0aafa1fdb60805c6b48aa4aa56311079b10an/aACRStealer