URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.43/files/6919303532/s95MQBL.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3773145
URL: http://130.12.180.43/files/6919303532/s95MQBL.exe
URL Status:Offline
Host: 130.12.180.43
Date added:2026-02-06 17:12:06 UTC
Last online:2026-02-07 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-02-06 17:13:13 UTC to abuse{at}virtualine[dot]org)
Takedown time:19 hours, 54 minutes Good (down since 2026-02-07 13:07:55 UTC)
Tags:c2-monitor-auto dropped-by-amadey MaskGramStealer ScarfaceStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-07s95MQBL.exeexe d5851b890ae91ec9db8188492e6d73c36c5ca157fa4b924ad9f5d10b7fdc2054n/a 
2026-02-07s95MQBL.exeexe 25c08817256845bbafed63ab1a5a579ac75d6052d679549e2ab7039bcf161a63n/a ScarfaceStealer
2026-02-07s95MQBL.exeexe fbe6d6ad999f6d7e3a63ca8c38ff1130302159704dbf0ae1cab652a353ec8615n/a ScarfaceStealer
2026-02-06s95MQBL.exeexe 6b89b739b52e5fd5a612512bc8631f8a514aa3d94300fffd0a437483a8299c0en/aMaskGramStealer