URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.43/files/7435145147/KZA247N.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3762481
URL: http://130.12.180.43/files/7435145147/KZA247N.exe
URL Status:Offline
Host: 130.12.180.43
Date added:2026-01-23 07:49:08 UTC
Last online:2026-01-24 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-01-23 07:50:19 UTC to abuse{at}virtualine[dot]org)
Takedown time:19 hours, 3 minutes Good (down since 2026-01-24 02:53:33 UTC)
Tags:c2-monitor-auto CobaltStrike link dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-23KZA247N.exeexe 196fb35653d58efd7f381a0c66ceab5bb26a20ac403448bda1b62a62bddae230n/aCobaltStrike
2026-01-23KZA247N.exeexe 16b655a9a39acb43e4dcb5e384b2dff66dc0c774a58d8714598b313fe1264c9cn/aCobaltStrike
2026-01-23KZA247N.exeexe 06696c638f9452200c468c5b5af0e59eb2365ada68539e9709d5f86f7d143586n/a CobaltStrike
2026-01-23KZA247N.exeexe 92a3391aaa92bf4060918d5de3ddb13c863ba62a9db327ca9efdb20ad7b56bcfn/aCobaltStrike