URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 130.12.180.2
Firstseen:2025-12-21 19:42:07 UTC
Total malware sites :34
Online malware sites :11 (32%)
Offline Malware sites :23 (68%)
Newest active malware site :2025-12-28 23:36:17 UTC
Oldest active malware site :2025-12-21 19:42:12 UTC (Age: 9 days, 17 hours, 57 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-21 19:42:12 130.12.180.2SBL690641AS214943 RAILNET- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-31 07:54:15http://130.12.180.2/main_i468Offlineelf ua-wget abuse_ch
2025-12-31 07:54:15http://130.12.180.2/main_spcOfflineelf ua-wget abuse_ch
2025-12-31 07:54:15http://130.12.180.2/main_arcOfflineelf ua-wget abuse_ch
2025-12-31 07:54:15http://130.12.180.2/main_i686Offlineelf ua-wget abuse_ch
2025-12-30 21:15:17http://130.12.180.2/1.shOfflinemirai ext sh ua-wget NDA0E
2025-12-30 17:24:18http://130.12.180.2/main_mpslOfflineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:17http://130.12.180.2/main_m68kOfflineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:17http://130.12.180.2/main_mipsOfflineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:17http://130.12.180.2/main_arm5Onlineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:17http://130.12.180.2/main_arm7Offlineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:17http://130.12.180.2/main_ppcOfflineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:17http://130.12.180.2/main_arm6Offlineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:17http://130.12.180.2/main_armOfflineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:13http://130.12.180.2/main_x86Offlineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:13http://130.12.180.2/main_sh4Offlineelf mirai ext ua-wget ClearlyNotB
2025-12-28 23:36:13http://130.12.180.2/main_x86_64Offlineelf mirai ext ua-wget ClearlyNotB
2025-12-25 19:21:07http://130.12.180.2/cbot/raw_cbot_debug.exeOfflineexe mirai ext opendir ua-wget NDA0E
2025-12-25 19:21:07http://130.12.180.2/cbot/cbot_debug.exeOfflineexe mirai ext opendir ua-wget NDA0E
2025-12-25 19:21:06http://130.12.180.2/cbot/cbot.exeOfflineexe mirai ext opendir ua-wget NDA0E
2025-12-25 19:21:06http://130.12.180.2/cbot/raw_cbot.exeOfflineexe mirai ext opendir ua-wget NDA0E
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnloonga...Onlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnpowerp...Offlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnm68kxnxnOnlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnmipsxnxnOnlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnmicrob...Offlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnsh4xnxnOnlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxni386xnxnOnlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnx86_64...Onlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnriscv3...Offlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnsh2xnxnOnlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnriscv6...Onlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:22http://130.12.180.2/bins/xnxnxnxnxnxnxnxnaarch6...Offlineelf mirai ext ua-wget abuse_ch
2025-12-22 07:00:21http://130.12.180.2/bins/xnxnxnxnxnxnxnxnor1kxnxnOnlineelf mirai ext ua-wget abuse_ch
2025-12-21 19:42:12http://130.12.180.2/run.shOnlinemirai ext sh ua-wget NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-12-31 13:36:182f5bb3f58d8da555b92f9bcef5546a530e5fabb1861e7199d64be747fe7dc227elf  
2025-12-31 13:34:42ac2f5faf62a144cee973138b94d2100fdc3766e3daf4f343c98f2fb7d9070f4celf  
2025-12-31 13:25:389c96b625c15c841588e1e8222b1b53e49108c80bf2af858d120fa0213324b6dbelfMirai
2025-12-31 13:01:527fedc8f52115affcc1857b23cd549a5c43010cd3fb222090b02bd6ca36b76760elfMirai
2025-12-31 12:34:3144182a22c99b651a77310586412792393a6e439bf6d6b50b2885c8f3c038d53felfMirai
2025-12-31 12:32:091bb03eff70e424ecd1ea9975e54682d32c891b2f2f9dda9c291d8dffc3480bf7elfMirai
2025-12-31 12:26:443e3cedaa0edd27da41eab7bad22d40b1f046275da25bab8ed6ddef1408c900a8elfMirai
2025-12-31 12:18:575ede1d8505787057d2f6f156718c6cd052a161b6ddad2da43a480e35a8d66d41elfMirai
2025-12-31 12:18:180d955d7236cff85f358465dfc81ea0ef5a76037bd639022a776d286a9e548140elfMirai
2025-12-30 21:15:17bf524afed3a4c56766d617b3909089d3193c65f7a62ebd13af2a49be8270ccdcshMirai
2025-12-30 17:24:1836a37ced893b0ab6400b785e14ee1c63e03f39cbb5bb18399b635ef59ffc3b14elfMirai
2025-12-28 23:36:17f0492645461def1452f4eb2d9ae14b218869b4dbc2093199042752b723a43bb7elfMirai
2025-12-28 23:36:17e4c9bb581e89de0ccdc2d33b90c2c3833492f4b6d238b0428ba5dfae94a348a4elfMirai
2025-12-28 23:36:17dabf196b20d87c5b615e6b4ba7b5a73caf04caed60f032d9454b61fd7d34fca6elfMirai
2025-12-28 23:36:170c84dd5e63104cb7ab0194b28f5c41adee4c460b54cfaa9f9dd855ebe589e18aelfMirai
2025-12-28 23:36:178fa63cf16bd8b5f0c267c99c6d62004db560a66360695c949b498231836df8ffelfMirai
2025-12-28 23:36:17e4c4775ebf8858e632497092e578940b33228349fadef0207aed99a7fb14d37belfMirai
2025-12-28 23:36:17b870b0c66e5cdbab21bc4d28c3e5e66a557f6d03ab30857312d445e6624d8894elfMirai
2025-12-28 23:36:130d7faa61a016d1ddbba591a09ce005623faced2ec2750b1f3148950f877a5b2aelfMirai
2025-12-28 23:36:135c8b91b9f5f0bcd72fd1ad5a8229396bfba43ecf1ce1f2eb3a483347652a876aelfMirai
2025-12-28 23:36:1370653f2079ed5ad5982aa4fbff4ac49c79a54b5ad6a0240fed2848897c00b17celfMirai
2025-12-25 19:21:07cce278f0b8b19cfc25545b9b2e126d0f7580d38234b2ecae79c7f32d92f9fcb4exe 
2025-12-25 19:21:0795ffe6faf5801d69c896b62ed1c2863447ed3cf3aff1c2acf450d46ed37a0a01exe 
2025-12-25 19:21:06c3ed2a612754f740a4653f0573f53c66364fdad535caa61ee37ca4948319c0a9exe 
2025-12-25 19:21:06bfc9e3ef619c60fde95cafb3b071837cf62b9252210f481fe5135d90d0289092exe 
2025-12-22 07:00:22a89f7f5f58288a91a02bdd8c4224fcd917d77ea5149771fd67433aa4deb6a49felfMirai
2025-12-22 07:00:226737ccd8d7dc5945638e935dd11e9aa635b39af9b125b1f62e197b04e9dda3d1elfMirai
2025-12-22 07:00:220b8d2a649987fca23d0e1965b42a2c7ed29040c40c990fb8861d4c728aa28103elfMirai
2025-12-22 07:00:22ba3287ed9914220cf4fcf4dd493c67292c4d1095d9ead5359bc3f38666335b1eelfMirai
2025-12-22 07:00:22624719a933aee7d9dbe2c8a899569d268e6ff13ba5172b6d535921660d6f8b6belfMirai
2025-12-22 07:00:226d6c9579ca57b1d3d5a3961be5ef90e7e145f071263042b23afa461e99e3713aelfMirai
2025-12-22 07:00:22fa14ecf837984c9b9259d1d9fcf84553c4a728d597bee8d623e1738cc178422aelfMirai
2025-12-22 07:00:2257bbaccebcaf065128022f68e01a91bdc58097e35ec9eac390e50f4ce219fed5elfMirai
2025-12-22 07:00:22509a2b093c0328576a3da7ad1bd5bb880c42526167519b95f0fd371bc68552e8elfMirai
2025-12-22 07:00:22f5b8a7db2093e66948c70002ca7de6cfa8da762c068bd7dfab4e3fdd51143da5elfMirai
2025-12-22 07:00:225e68511dfe9da9a6d1e081d058b7dc3bd1ddb189bfdd748c629aae43caf335bdelfMirai
2025-12-22 07:00:22888ed48db5837610a78077720a2ac0ec8ab0777d3b42e07182332ddb21eb8d91elfMirai
2025-12-22 07:00:219726543059a9ce755f9ad2edd8a28acefbf31a09d8420468aa5fa445c8f595c2elfMirai
2025-12-21 19:42:12538637349b68660afe5b7169ee6195be8c1163e8502b27bebd3fa3fb6791f3dfshMirai