URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.43/files/748049926/f12BhQB.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3776572
URL: http://130.12.180.43/files/748049926/f12BhQB.exe
URL Status:Offline
Host: 130.12.180.43
Date added:2026-02-12 17:58:08 UTC
Last online:2026-02-15 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-02-12 17:59:11 UTC to abuse{at}virtualine[dot]org)
Takedown time:2 days, 6 hours, 51 minutes Poor (down since 2026-02-15 00:50:47 UTC)
Tags:c2-monitor-auto dropped-by-amadey GoProxy

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-13f12BhQB.exeexe e5f83c66e93fc7e36cd7141ef14520ddeb95e90a8d86db4882fd9c04c68a1aa0n/aGoProxy
2026-02-13f12BhQB.exeexe a33eaafe9389baebab230897aa1f611923aa8a7e62d3bdc49d7dcac9be49b4ebn/a GoProxy
2026-02-13f12BhQB.exeexe 48a27aab8f379d69f58ed2a12af7aea3984bfd3815211d235b2975c7083c0df4n/a GoProxy
2026-02-13f12BhQB.exeexe 6a0568759075b0a354ff21e0e0be2282bdf59c34ec61d3d91718c87507b0fbd6n/aGoProxy
2026-02-12f12BhQB.exeexe af6848386a183fb7718cc808ba8a6b8c3d7565b435acbd2beebe079018da50d0n/aGoProxy