URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.43/vidar/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3743615
URL: http://130.12.180.43/vidar/random.exe
URL Status:flame Online (spreading malware for 2 months, 7 days, 7 hours, 30 minutes)
Host: 130.12.180.43
Date added:2025-12-25 20:21:06 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-12-25 20:22:12 UTC to abuse{at}virtualine[dot]org)
Tags:Amadey c2-monitor-auto dropped-by-amadey Smoke Loader link Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-27random.exeexe ab4a92b1b4fd0320e7a13519c8c2b8fa8a828ec56db52864dd70dc48061604b3n/a Amadey
2026-02-21random.exeexe e719588de94e1f43ddcf69ceb6a0ce28d1bc13a32d40142c135188cb4a2361f8n/aSmoke Loader
2026-02-13random.exeexe c489a4ede6af77cf83860b7f7db84cc866c24c4130fcd87bd54a97e8a04b30bfn/a Vidar
2026-02-07random.exeexe a7469b98efceb423c35bb888792aa94041f046b64fce2203e32a1afc03797bb7n/a Vidar
2026-02-03random.exeexe b9b3e72172d5ec9f1409d93af1e989e65065872311e519a55e6b66fef420d3f1n/a Amadey
2026-01-30random.exeexe 500ed5f0da5e4c64ef5a9e6c7aa08dfd223446fd4f874fdde69ce9ea4217a497n/a Vidar
2026-01-23random.exeexe e817f23928542ddd3b617153beee06fefa09bb177534fe739b2b8d1e5250111dn/a Vidar
2026-01-18random.exeexe 30b914a7ca0033bcb3f8c6063cbb3a308f40482c1db797f42ee5f96a6d930ca1n/a Vidar
2026-01-09random.exeexe c29e1a848907bb8e00efb784b9a0b24a724d2d4ad9cc1fa70070a9d92f7c2570n/a Vidar
2026-01-02random.exeexe fa42334cbd4f9fcc80b8d980649758e430f56d3d92397dee0079b70b3dc658a9n/a Vidar
2026-01-02random.exeexe cecb4f2b86fd4228668bd1f0bfbf989bb11f419f1fddfaad15ba352611c535d7n/a Vidar
2026-01-02random.exeexe 4bcb4afea83aa65c937e13b97c817a856b0cc9e4c13a6a4a4e15d647a7c3c3ban/a Vidar
2025-12-26random.exeexe d8dbcbc2ec0eac366a9c7a8f106cfab4a852d4c4cee81eb0a58396b78bb2b9afn/a Vidar
2025-12-26random.exeexe a7ccbd569505d6e4a9cad09d97312bb4c6e38d8b9bc2e6e7bfcaf3d2bd767e32n/aVidar
2025-12-25random.exeexe ef6ce6a5f34ab55e4898cb9b895d9832d66f0b0c3757a4e446b42cf6967f7da8n/aVidar