URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.43/vidar/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3743615
URL: http://130.12.180.43/vidar/random.exe
URL Status:flame Online (spreading malware for 1 day, 0 hours, 48 minutes)
Host: 130.12.180.43
Date added:2025-12-25 20:21:06 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-12-25 20:22:12 UTC to abuse{at}virtualine[dot]org)
Tags:c2-monitor-auto dropped-by-amadey Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-26random.exeexe d8dbcbc2ec0eac366a9c7a8f106cfab4a852d4c4cee81eb0a58396b78bb2b9afn/a Vidar
2025-12-26random.exeexe a7ccbd569505d6e4a9cad09d97312bb4c6e38d8b9bc2e6e7bfcaf3d2bd767e32n/aVidar
2025-12-25random.exeexe ef6ce6a5f34ab55e4898cb9b895d9832d66f0b0c3757a4e446b42cf6967f7da8n/aVidar