rabbids.cc: a Windows infostealer download site that uses DLL sideloading, and what to do if you ran a file from it
rabbids.cc is a web address that URLhaus lists for 5 malware downloads, tagged infostealer, stealer and dll-sideloading, among them a zip archive and a file named 7za.exe that were still online when we checked. If you ran a file from it on Windows, disconnect the PC, change your passwords from another device, then scan the PC offline.
Facts checked October 10, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a zip archive, an executable or a program that came from rabbids.cc usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove rabbids.cc (infostealer files with DLL sideloading) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Rabbids.cc (infostealer files with DLL sideloading): summary
| Type | A malware download host for Windows: URLhaus lists a zip, an exe and three php files tagged infostealer |
|---|---|
| Risk | High if a file from it ran: passwords, sessions, crypto and a second hidden program are possible |
| Symptoms | Often none. A zip or 7za.exe from an unknown site, login alerts you did not cause or messages you did not send are the signs |
| How to get rid of it | Disconnect, change passwords from another device, end sessions, move crypto, run a Microsoft Defender Offline scan, then back up documents and reinstall Windows if in doubt |
| Our check (10 October 2026) | One visit: HTTP 200 and an empty page. A quiet site clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 18 September 2026; malware URLs reported 28 September 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows, judging by the exe file and the dll-sideloading tag; not confirmed |
|---|---|
| Detection names | No Microsoft detection name is known for these files, because we did not open them. The URLhaus tags are infostealer, stealer, dll-sideloading, Lzveil and Yogi |
| Name | Rabbids.cc |
| Domain registered | 18 September 2026 |
| Evidence | 5 write-ups by security sites; details still limited |
| First seen | 28 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 10 October 2026 |
Facts checked on 10 October 2026 against our copy of the URLhaus data for rabbids.cc, one browser test of our own, the registration record, the MITRE ATT&CK page on DLL search order hijacking, the Sigma rule for 7za.dll sideloading, Microsoft's page on DLL security and Microsoft's page on Defender Offline.
We did not download the files and we infected no PC; the cleaning steps follow Microsoft and were not tried on a live infection.
What rabbids.cc is, and what we know about it
rabbids.cc is a web address, not a program on your PC. The abuse.ch project URLhaus lists it as a place that served malware. We found no public write-up of this domain, so this page rests on the URLhaus rows in our database, one visit of our own, the registration record and what Microsoft and MITRE document about the technique in the tags.
- 1
What URLhaus lists
Five file addresses on this host, every one with the threat type malware_download, all added on 28 September 2026 between 06:11:19 and 06:11:20 UTC by one reporter account named hatrask. The files are /encrypted/1.zip, /encrypted/7za.exe, /start.php, /screen.php and /end.php.
- 2
What the tags say
All five rows carry the same twelve tags, including infostealer, stealer, dll-sideloading, exfiltration, surveillance, c2, dropper and zip. Two more tags, Lzveil and Yogi, look like names the reporter gave to a family or a kit. We found no source that explains either word.
- 3
What is still online
When we read the feed on 10 October 2026, the zip and the 7za.exe file were marked online. The three php files were marked offline. Online means the reporting system still got an answer for that address at its last check, not that the file is safe to open.
- 4
What we could not confirm
We downloaded nothing, so we do not know what the archive holds, what the stealer collects or where it sends data. The tags are the reporter's labels, not our finding.
- 5
What it means for you
If the name only showed up in a block list or a security scan, nothing is installed because of it. If you downloaded and ran a file from it, treat the PC as compromised and follow the plan on this page.
- Kind of threat
- A malware download host: a zip, an exe and three php files, all tagged infostealer
- Malware family
- Not confirmed. The reporter's tags are Lzveil and Yogi; we found no public analysis of either
- Registration
- Registered 18 September 2026 through NICENIC International Group, expires 18 September 2027, record last changed 6 October 2026. The owner is not shown
- URLhaus entries
- 5 file addresses, all added on 28 September 2026; 2 online and 3 offline when we read them
- Platform
- Windows, judging by the exe file and the dll-sideloading tag. No source confirms it
What rabbids.cc (infostealer files with DLL sideloading) does on an infected PC
What our check on 10 October 2026 showed, and what it cannot show
We opened https://rabbids.cc/ once, from Lithuania, in an automated Chromium browser set to English. The server answered with HTTP status 200 and an empty page. That is not a clean result. A malware host usually serves files to people who know the exact path, not a front page.

Our site test, 10 October 2026
- The home page was blankThe server answered with status 200, but the page had no title, no text and no links. The files sit on deeper paths, so a blank front page tells you nothing about them.
- Notification request, pop-ups, redirects, ad networksNone seen on this one visit. A host of this kind serves files, not advertising.
- Why one quiet visit proves littleA server can answer differently by country, by browser, by referrer or on a second visit. Nothing on this one visit is not the same as nothing ever.
- URLhaus listing5 malware addresses with infostealer tags, 2 of them online on 10 October 2026, 12 days after the reports.
- Registration dataCreated 18 September 2026, ten days before the reports, with a record change on 6 October 2026. It does not show who owns the name or why it changed.
Dangerous: treat it as an infostealer download host Our test was one visit to an empty page and proves nothing either way. The rating rests on the URLhaus reports, and two of the files were still online.
From registration to our test: the dates we have
The history is short. We have a registration date, one burst of reports lasting two seconds, a record change eight days later and our own visit. We know nothing about what the name was used for in between.
18 September 2026
The domain is registered
The registration record gives this creation date, with NICENIC International Group as registrar and a one year term ending 18 September 2027. We do not know who registered it.
28 September 2026, 06:11 UTC
Five files are reported within two seconds
URLhaus receives /end.php, /screen.php, /encrypted/1.zip, /start.php and /encrypted/7za.exe between 06:11:19 and 06:11:20 UTC. Every row carries the same tags, and one reporter filed them all.

The URLhaus entries for rabbids.cc, summarised from our copy of the feed on 10 October 2026. 6 October 2026
The registration record changes
The record shows a last change on this date. It does not say what changed. It may be a routine update, and we found no source that tells which.
10 October 2026
Our visit finds an empty page
Our browser reaches https://rabbids.cc/ and gets HTTP 200 with a blank page. URLhaus still lists /encrypted/1.zip and /encrypted/7za.exe as online.
We could not read the URLhaus pages themselves because they ask for a browser check. The entries above come from the same feed as held in our own database.
The five files: what each name suggests, and what we do not know
File names are weak evidence. We list what each one could be and mark which statements are only a reading of the name and tags.
| File on rabbids.cc | What URLhaus says | What it may be (our reading) |
|---|---|---|
| /encrypted/1.zip | Online, tagged zip, dropper, infostealer and dll-sideloading, added 28 September 2026 | A zip archive, probably the package a victim is given. The folder name encrypted may mean the content is protected from scanners. Not confirmed |
| /encrypted/7za.exe | Online, same tags, added 28 September 2026 | The name is the same as the 7-Zip command line tool. In a sideloading chain a real tool is paired with a planted DLL. We did not open the file, so it may or may not be the real tool |
| /start.php | Offline, same tags, added 28 September 2026 | A server side script. The tags c2 and exfiltration suggest it talks to the operator. Its role is not confirmed |
| /screen.php | Offline, same tags, added 28 September 2026 | A server side script. The name and the surveillance tag could point to screenshots, but that is only a guess from the word |
| /end.php | Offline, same tags, added 28 September 2026 | A server side script that may mark the end of a session. Not confirmed |
Three php names that read as start, screen and end would fit a program that reports its progress to a server. That is a pattern, not a fact, and we saw none of the traffic.
How DLL sideloading works, and why a tag like this matters
The tag dll-sideloading names a method, not a product. MITRE and Microsoft describe the method in general terms, and we use those pages to explain it. We did not run the files, so we cannot say which program or which DLL these ones use.
- 1
How Windows looks for a DLL
Microsoft says that when a program loads a DLL without a full path, Windows searches a fixed list of folders. With safe search mode on, the first folder is the one the application was loaded from, then the system folders, the current directory and the PATH folders.
- 2
How an attacker uses that order
MITRE describes sideloading as placing a malicious DLL next to a legitimate, often signed program that loads it. The program starts as normal, finds the planted file first and runs its code.
- 3
Why it hides well
According to MITRE, the payload then runs under a trusted process, and the planted DLL may also load the real one so the program appears to work. A tool that looks at program names alone may see only a familiar name.
- 4
Why 7za is in the picture
A public detection rule in the Sigma collection flags a file named 7za.dll that a process loads from outside the Program Files folders. The rule is rated low severity because legitimate programs in AppData can use that DLL. We found no source that links it to this host.
- 5
What you can check
A copy of a tool that sits in your Downloads or Temp folder, beside a DLL you did not install, is a reason to stop. A real installed 7-Zip lives in Program Files and does not need a zip from an unknown site.
What rabbids.cc (infostealer files with DLL sideloading) can steal or download
What an infostealer takes, and what the tags promise
The tags say infostealer, exfiltration and surveillance. We have no analysis of these files, so the list below is what stealers in general go after, not a list of what these files took.
What a stealer on a Windows PC may collect
- Saved browser logins
- Session cookies
- Autofill and card data
- Crypto wallet files
- Documents on the desktop
- Screenshots
- Messenger and game tokens
- System details
The tag surveillance and the name screen.php may mean the program also takes screenshots. We cannot confirm it. What matters is the habit it implies: assume anything you typed or saved on that PC was seen.
Stolen cookies are the quiet part. A thief who holds a valid session cookie can be signed in to an account without the password, so a password change alone may not end it.
What this can cost you
Seeing this name in a log costs nothing. The risks below apply to a PC that really ran a file from this address.
- High
Stolen passwords and sessions
A stealer's main job is to copy saved logins and cookies. Email, bank, work and social accounts are the first to go.
- High
Crypto taken for good
A moved balance cannot be taken back. Wallet files and recovery phrases on the PC are a prime target for programs of this kind.
- Medium
A second program on the PC
A dropper may fetch more malware after the first step. The tag dropper on these rows makes that a real possibility, though we did not see it.
- Medium
Fraud on your accounts
With your email and a session, a thief can reset other accounts, ask your contacts for money or place orders.
- Low
Nothing, if you only saw the name
A name in a firewall log or a blocked link is not an infection.
What you might see, and why you may see nothing
Stealers try not to be noticed. The signs below follow from how such programs work, and none of them proves infection alone.
| Sign | What it means |
|---|---|
| A zip or exe you downloaded from an unknown site | The strongest sign. If you ran it, assume the PC is exposed |
| An unknown folder with a copy of a tool beside a DLL | Check Downloads, Temp and AppData for a 7za.exe or a DLL you did not add |
| Login alerts or password reset mails you did not ask for | Someone may be using a stolen password or a stolen session |
| Messages sent from your accounts that you did not write | A sign that a thief has your session |
| Nothing at all | The program may have run once, copied its data and stopped |
How to check the PC for rabbids.cc (infostealer files with DLL sideloading)
How people meet a download host like this
No source tells us how anyone reached rabbids.cc. The routes below are common for stealers in general, and we mark them as such.
- 1
A free program that is not free
Cracks, keygens and pirated installers are a common cover for stealers. A zip with a password and a readme is typical.
- 2
A fake download page
A page that looks like a tool's own site offers an archive. The real tool's address is a short check away.
- 3
A link in a chat or a mail
A message with a link to a zip and a request to open it. We do not know of such a message for this host.
- 4
A line in a log
If you only found rabbids.cc in a firewall or DNS log, find out which program asked for it. That program is the suspect.
Check your PC first, before you delete anything
The question that matters is whether a file from this address ran on your PC. The checks below change nothing.

- 1
Look at your downloads
Open File Explorer > Downloads and sort by date. Look for a zip, a 7za.exe or a program that you did not mean to get around the time you visited an unfamiliar site.
- 2
Read the browser history
In Chrome and Edge press Ctrl+H and search for rabbids. In Firefox press Ctrl+H, then search the sidebar. A hit tells you the day and the page you were on.
- 3
Check Windows Security history
Open Windows Security > Virus & threat protection > Protection history and read the recent items. Blocked or quarantined items from that day are a clue.
- 4
Look at running programs
Press Ctrl+Shift+Esc to open Task Manager. On the Details tab look for a 7za.exe or a program with a strange name that runs from AppData or Temp.
- 5
Know what a clean check means
These checks cannot look inside a hidden program. A stealer may have run once and left, so a quiet PC does not prove it was never touched.
How to remove rabbids.cc (infostealer files with DLL sideloading)
How to remove rabbids.cc
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to rabbids.cc or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever rabbids.cc installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Scan from outside Windows: Microsoft Defender Offline
An offline scan runs before the normal Windows starts, so a hidden program cannot hide from it as easily. Microsoft says it is meant for malware that tries to bypass the Windows shell.
- 1
Do the account steps first
Before you scan, use another device to change your passwords, as described in the next section. A stealer may already hold the old ones, and the scan does not undo that.
- 2
Get the PC ready
Save open files and quit your programs, because the PC restarts by itself. The scan needs an administrator account and a working Windows Recovery Environment. In an administrator Command Prompt type
reagentc /info. If it says Disabled, typereagentc /enable. Microsoft warns that with recovery off the scan does not start and no error appears. - 3
Pause BitLocker
A PC with BitLocker on the system drive may ask for the recovery key at the restart. Suspend BitLocker first, using Microsoft's linked instructions.
- 4
Launch it from Windows Security
Go to Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Offline scan and press Scan now. Accept the prompts. Windows signs you out and boots into the scan, which Microsoft says takes about 15 minutes. As an administrator you can also type
Start-MpWDOScanin PowerShell. - 5
Read the result
When Windows returns, open Windows Security > Virus & threat protection > Protection history. On Windows 10 the same screen is under Settings > Update & Security > Windows Security. Microsoft lists Windows on ARM as unsupported, and Defender Antivirus must be your main antivirus.
- 6
Treat a clean report with care
No detection is not proof of a clean PC, because we do not know what these files install. If you ran one of them, copy your documents off and reinstall Windows.
If you use a Mac, an iPhone or an Android phone
The exe file and the dll-sideloading tag point at Windows. We found nothing that says these files run on anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | An exe file and a DLL technique are Windows things. What a Mac visitor would have received is unknown | Nothing to remove for these files. Change any password you typed into a page from this site |
| iPhone or iPad | iOS does not run Windows programs | Nothing to delete. Change any password you entered on a page from this site |
| Android | No source we read mentions it | Nothing to delete for these files. Change any password you entered |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything that was on it, which the attackers may already have. The order matters: other device first, then crypto, then the PC.
- 1
New passwords, from a different device
Pick up your phone or a family member's laptop. Begin with the email account, since it resets everything else, then bank, work and social logins. Anything typed or saved on the affected PC should be assumed seen.
- 2
End every open session
Stolen cookies can keep a thief signed in after a password change. Use the sign out everywhere option in each account that matters, and cancel any API tokens, SSH keys or cloud keys that lived on the PC.
- 3
Crypto before anything else
If a wallet or its recovery phrase sat on the PC, create a new wallet on a clean device and send the funds there at once.
- 4
Remove saved passwords from the browser
In Chrome open Settings > Autofill and passwords > Google Password Manager. In Edge open Settings > Profiles > Passwords. Delete what you saved on the PC after you have changed it.
- 5
Add a second sign in step
Prefer an authenticator app or a hardware key over text messages. A stolen password alone then does not let someone in at a fresh login.
- 6
Save documents, then reset Windows
Copy documents and photos only, never programs or archives, to an external drive. On Windows 11 open Settings > System > Recovery; on Windows 10 open Settings > Update & Security > Recovery. Choose to reset the PC and remove everything.
- 7
Watch the money
For the next few weeks read your bank, email and crypto history for anything you did not do, and call your bank the same day if you find it.
Keep a Windows PC out of this kind of trap
The rule that stops this chain is short: an archive from a site that offers paid software for free is not a gift.
Do
- Get programs from the maker's own site or from the Microsoft Store.
- Install Windows and browser updates, and leave Windows Security switched on.
- Use a password manager and an authenticator app on your key accounts.
- Keep one backup on a drive that stays unplugged.
- Check where a tool lives. A real 7-Zip sits in Program Files, not in a Downloads folder.
Don't
- Never run cracks, keygens or pirated installers.
- Never open an archive that asks you to switch off your antivirus first.
- Never trust a tool because its file name looks familiar. MITRE says sideloading hides behind trusted programs.
- Never keep a crypto recovery phrase in a file on the PC.
- Never read a quiet scan as proof that you are safe.
Questions about rabbids.cc (infostealer files with DLL sideloading)
What is rabbids.cc?
rabbids.cc is a domain name that URLhaus, the malware tracker run by abuse.ch, lists for malware downloads. Five file addresses were added on 28 September 2026 within two seconds, all tagged infostealer.
The registration record shows creation on 18 September 2026 through NICENIC International Group. When we visited on 10 October 2026 the home page was empty, and two of the files were still online. We found no public write-up of it.
Is rabbids.cc a virus?
A domain name is not a virus, but this one is listed as a source of infostealer files. We did not download them, so we cannot say exactly what they do.
Treat the address as dangerous and do not open it to fetch files. Reading this page cannot infect you. The danger is a zip or program that you ran from the site.
What are Lzveil and Yogi?
Lzveil and Yogi are tags that the reporter added to the URLhaus entries. They look like names of a malware family or a kit, but we found no public source that explains either one.
We therefore do not claim to know the family. What the other tags say is more useful:
- infostealer
- dll-sideloading
- exfiltration describe a program that steals data through a planted DLL
What is DLL sideloading?
DLL sideloading is a method in which a malicious DLL is placed next to a legitimate program that loads it. MITRE says the payload then runs under a trusted process and may load the real DLL so the program appears to work.
Microsoft explains that Windows looks first in the folder the application was loaded from, which is why a planted file can win.
What is 7za.exe, and is it dangerous?
7za.exe is the file name of a standalone command line version of the 7-Zip archive tool. The real tool is harmless.
URLhaus lists a file with this name on rabbids.cc as online with infostealer tags, and we did not open it, so we cannot say whether it is the real tool or something else. A copy from an unknown site should not be run.
What should I do if I ran a file from rabbids.cc?
Disconnect the PC from the internet first. Then use another device to change your passwords, starting with email, and sign out of all sessions. Move any crypto to a new wallet created on a clean device.
After that run a Microsoft Defender Offline scan, and if you are unsure, copy your documents to a drive and reset Windows with everything removed.
Will a Microsoft Defender Offline scan be enough?
It is a good step but not proof. Microsoft says the scan runs outside the normal Windows environment and targets malware that tries to bypass the shell, and it takes about 15 minutes.
No detection does not clear the PC, because we do not know what these files install. The scan also cannot give back passwords that were already copied, so change them anyway.
Can I recover my stolen accounts?
Often yes, if you act fast. Use another device to change your email password first, because it resets everything else. Then sign out all sessions, since a stolen cookie can keep a thief in.
Turn on an authenticator app and read the recent activity page of each account. If money moved, call your bank at once and report the loss.
Does this affect my Mac or phone?
Almost certainly not directly. The exe file and the dll-sideloading tag point at Windows, and we found no source that says these files run on a Mac, an iPhone or an Android phone.
If you typed a password into a page from this site on any device, change that password. Otherwise your Mac or phone needs no cleaning because of this address.
Will Fortect remove rabbids.cc?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For rabbids.cc, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): host page for rabbids.cc (entries read from our copy of the feed) (read October 10, 2026)
- MITRE ATT&CK: Hijack Execution Flow, DLL Search Order Hijacking (T1574.001) (read October 10, 2026)
- Sigma rule: Potential 7za.DLL Sideloading (detection.fyi) (read October 10, 2026)
- Microsoft Learn: Dynamic-Link Library Security (read October 10, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (read October 10, 2026)