URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.43/files/6382108206/AoA6ARH.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3762806
URL: http://130.12.180.43/files/6382108206/AoA6ARH.exe
URL Status:flame Online (spreading malware for 13 hours, 10 minutes)
Host: 130.12.180.43
Date added:2026-01-24 00:17:06 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-01-24 00:18:10 UTC to abuse{at}virtualine[dot]org)
Tags:c2-monitor-auto CoinMiner dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-24AoA6ARH.exeexe 87a27b849013f8d464449d01b7093fe307958f9448a0b7faac5ff1f79fbda888n/a CoinMiner
2026-01-24AoA6ARH.exeexe dfc6c1b5ffbf483ff9e3b6243fc736f6b08c26f2cf8d4b1d30e933c4b4ca7d6en/a CoinMiner
2026-01-24AoA6ARH.exeexe 6abbe6ae99e3ae4311804d63dcf9e34c6a486432daadf6bfdb988a0b1e6fd107n/aCoinMiner
2026-01-24AoA6ARH.exeexe ac035aeacf8e68baf9d44aadc29d2036d9ad86578622f3d691b58277412dcb37n/aCoinMiner