URLhaus Database

You are currently viewing the URLhaus database entry for http://43.156.63.124:64494/02.08.2022.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3712904
URL: http://43.156.63.124:64494/02.08.2022.exe
URL Status:flame Online (spreading malware for 6 months, 8 days, 7 hours, 15 minutes)
Host: 43.156.63.124
Date added:2025-11-20 16:57:10 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-11-20 16:58:17 UTC to abuse{at}tencent[dot]com)
Tags:censys CobaltStrike link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-0402.08.2022.exeunknown a4edd89543b784fd0c7823cc1519580fc6e66610aac1439f14b849dd1e5feab0n/a 
2026-03-0202.08.2022.exeunknown 5fadae54ec73c3078d9137999289bbeead49ee0167fb6cc61f251bc40deb11d0n/a 
2026-02-2402.08.2022.exeunknown 8c217ef731d2be8021f5f5006514e46e32486ac38a5650dba0758b01ee4b2805n/a 
2026-02-0202.08.2022.exeunknown 18a8a13763524b73dfe9178b1cb89a1d164cef3ecd971a486e6b093fb8ea0ed5n/a 
2026-01-2902.08.2022.exeunknown 157e50161f3412e71941b149ebd5895415c7c1cd00e37145d476f509cf71a0f4n/a 
2025-11-2002.08.2022.exeunknown 40ef98e3251741b57792a42246eb238c4c12936d2db00bef2b8389b834ce7b52n/a