URLhaus Database

You are currently viewing the URLhaus database entry for http://143.92.43.231:8011/02.08.2022.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3660513
URL: http://143.92.43.231:8011/02.08.2022.exe
URL Status:flame Online (spreading malware for 7 months, 23 days, 2 hours, 11 minutes)
Host: 143.92.43.231
Date added:2025-10-06 17:04:09 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-10-06 17:05:31 UTC to cs[dot]mail{at}ctgserver[dot]com)
Tags:censys CobaltStrike link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-2802.08.2022.exeunknown 966defeb5f18b740f90ea2f79f924537f3ca4fa7bfe137bc07b3959dc7df58f2n/a 
2025-12-2302.08.2022.exeunknown 24b3b2865ff98293c56fddf35f6cb18445c90b2ca36dd21597027e9810871b6cn/a 
2025-10-0602.08.2022.exeunknown 966f2319093ffe881ce1018d78c4895c895ed23beac14dfb9aaade0974aaf619n/a