URLhaus Database

You are currently viewing the URLhaus database entry for http://43.166.246.26:8001/02.08.2022.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3634070
URL: http://43.166.246.26:8001/02.08.2022.exe
URL Status:flame Online (spreading malware for 10 months, 4 days, 13 hours, 4 minutes)
Host: 43.166.246.26
Date added:2025-09-28 16:46:22 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-28 16:47:16 UTC to qcloud_net_duty{at}tencent[dot]com)
Tags:censys CobaltStrike link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-2902.08.2022.exeunknown 2cac209b082e97f6e37981a476efec44ee23f5a354c4406d801695e14ff3c4c0n/a 
2025-10-0902.08.2022.exeunknown a5abdf1e5013e8de9fc4a6050346da9bb4014fc2d13a36019d893fcfc1e12c9en/a 
2025-09-2802.08.2022.exeunknown dd434a728401fdf0ddb43bb50d1a4accb0044f60830ac13619e6a30ef6c5d151n/a