URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.43/files/klon/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3765288
URL: http://130.12.180.43/files/klon/random.exe
URL Status:flame Online (spreading malware for 8 days, 2 hours, 35 minutes)
Host: 130.12.180.43
Date added:2026-01-28 21:10:07 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-01-28 21:11:12 UTC to abuse{at}virtualine[dot]org)
Tags:dropped-by-amadey fbf543 SalatStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-05random.exeexe c2cd34c0f4295339c1d611c5a9a4847be9da704e3454fe781f4af47540c0bb9dn/a
2026-02-03random.exeexe 01742ac49170d0604f42974eeba7cd94a7a3b0e9b695a7da000b1deeb9efeecen/a 
2026-01-28random.exeexe 48b66a15b70f7b3b7f26ee10287d292c6c68ea3d4c540af550564d692f67a982n/aSalatStealer