URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 130.12.180.20
Firstseen:2025-12-24 22:58:04 UTC
Total malware sites :42
Online malware sites :13 (31%)
Offline Malware sites :29 (69%)
Newest active malware site :2025-12-25 03:16:06 UTC
Oldest active malware site :2025-12-25 03:11:09 UTC (Age: 12 hours, 55 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-12-24 22:58:09 130.12.180.20SBL690641AS214943 RAILNET- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-12-25 07:55:12http://130.12.180.20:52603/i486Offlineelf ua-wget abuse_ch
2025-12-25 07:55:12http://130.12.180.20/i486Offlineelf ua-wget abuse_ch
2025-12-25 03:16:06http://130.12.180.20:52603//arm5Onlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-25 03:11:10http://130.12.180.20:52603/cat.shOfflinegeofenced mirai ext sh ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/x86_64Onlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/m68kOnlineelf geofenced m68k mirai ext ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/mpslOnlineelf geofenced mips mirai ext ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/arm7Onlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/ppcOnlineelf geofenced mirai ext PowerPC ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/spcOnlineelf geofenced mirai ext sparc ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/arm6Onlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/x86Onlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/arm5Onlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/sh4Onlineelf geofenced mirai ext SuperH ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/arm4Onlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-25 03:11:09http://130.12.180.20:52603/mipsOnlineelf gafgyt ext geofenced mips ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/x86_64Offlineelf geofenced ua-wget USA x86 botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/arm5Offlinearm elf geofenced ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/cat.shOfflinegeofenced sh ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/spcOfflineelf geofenced sparc ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/m68kOfflineelf geofenced m68k ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/arm6Offlinearm elf geofenced ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/ppcOfflineelf geofenced PowerPC ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/arm4Offlinearm elf geofenced ua-wget USA botnetkiller
2025-12-25 00:50:08http://130.12.180.20:31735/sh4Offlineelf geofenced SuperH ua-wget USA botnetkiller
2025-12-25 00:50:07http://130.12.180.20:31735/x86Offlineelf geofenced ua-wget USA x86 botnetkiller
2025-12-25 00:44:05http://130.12.180.20:31735/arm7Offlinearm elf geofenced ua-wget USA botnetkiller
2025-12-25 00:37:05http://130.12.180.20:31735/mpslOfflineelf geofenced mips ua-wget USA botnetkiller
2025-12-25 00:37:05http://130.12.180.20:31735/mipsOfflineelf geofenced mips ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/arm7Offlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/cat.shOfflinegeofenced mirai ext sh ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/sh4Offlineelf geofenced mirai ext SuperH ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/x86_64Offlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-12-24 23:05:11http://130.12.180.20/spcOfflineelf geofenced mirai ext sparc ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/ppcOfflineelf geofenced mirai ext PowerPC ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/m68kOfflineelf geofenced m68k mirai ext ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/arm4Offlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/arm5Offlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/arm6Offlinearm elf geofenced mirai ext ua-wget USA botnetkiller
2025-12-24 23:05:11http://130.12.180.20/x86Offlineelf geofenced mirai ext ua-wget USA x86 botnetkiller
2025-12-24 22:58:09http://130.12.180.20/mipsOfflineelf gafgyt ext geofenced mips ua-wget USA botnetkiller
2025-12-24 22:58:09http://130.12.180.20/mpslOfflineelf geofenced mips mirai ext ua-wget USA botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-12-25 13:21:54f970290ff41ba899fedea4999e76461860b7cdab86a1847193302edb0ee691baelfMirai
2025-12-25 03:16:06fc542ad670c36e48b6bf573678e5e81fe884d231807256ecd06fa88801cb8eaaelfMirai
2025-12-25 03:11:10d2e8ad3035bf734c4ab18d298b44dae38c3841eb5e37532bef4ca89e3bb8c35bshMirai
2025-12-25 03:11:09e2f49b929531ddce009e62e076af65a97785fe9732012fb13e968ffab3164f43elfMirai
2025-12-25 03:11:09d908d2f0b4114165079510ef8fc762c6b6cec60eea6dec514d683f3e67f55680elfGafgyt
2025-12-25 03:11:0942719d96f3b14272254cbd68c4ea3e02900a517a501f8a94440cf162689e6b0aelfMirai
2025-12-25 03:11:097916e2f6e47d71fcc0a48bf85d4bce2a61623035bc91eda55f036f1f6482a956elfMirai
2025-12-25 03:11:09fc542ad670c36e48b6bf573678e5e81fe884d231807256ecd06fa88801cb8eaaelfMirai
2025-12-25 03:11:0930da945d7e5500938299cb12b475f94e3354dfdcfb5d591128668a3b5d4de483elfMirai
2025-12-25 03:11:09afd23239ac37840687f51cdc8cc0e5c1ab0f62bfcc861427a092bd21e07d8deeelfMirai
2025-12-25 03:11:09f4c538b4c55ad7f1dcc1dc160b373386aa0b11de48528ac5338ea58913e42900elfMirai
2025-12-25 03:11:090ddb8750a2234f53bebd468ede3922e59d69845d47c81967709bb9ed729a2717elfMirai
2025-12-25 03:11:094f581e30be9df11bcab26c70caf17a0161cf2acaf676371ba0aa5aabc7e5d371elfMirai
2025-12-25 03:11:09f20dd3de2b928c15faff2a8b7233b3918a3922f53f61ce7e02a7e0f1b691be1aelfMirai
2025-12-25 03:11:09b041660f92a91d789663cf2b84acb7045c27fc2287283b0dd3bcb4cea0ebb9d8elfMirai
2025-12-24 23:05:1130da945d7e5500938299cb12b475f94e3354dfdcfb5d591128668a3b5d4de483elfMirai
2025-12-24 23:05:11f20dd3de2b928c15faff2a8b7233b3918a3922f53f61ce7e02a7e0f1b691be1aelfMirai
2025-12-24 23:05:11f4c538b4c55ad7f1dcc1dc160b373386aa0b11de48528ac5338ea58913e42900elfMirai
2025-12-24 23:05:11fc542ad670c36e48b6bf573678e5e81fe884d231807256ecd06fa88801cb8eaaelfMirai
2025-12-24 23:05:1142719d96f3b14272254cbd68c4ea3e02900a517a501f8a94440cf162689e6b0aelfMirai
2025-12-24 23:05:11b041660f92a91d789663cf2b84acb7045c27fc2287283b0dd3bcb4cea0ebb9d8elfMirai
2025-12-24 23:05:114f581e30be9df11bcab26c70caf17a0161cf2acaf676371ba0aa5aabc7e5d371elfMirai
2025-12-24 23:05:110ddb8750a2234f53bebd468ede3922e59d69845d47c81967709bb9ed729a2717elfMirai
2025-12-24 23:05:11afd23239ac37840687f51cdc8cc0e5c1ab0f62bfcc861427a092bd21e07d8deeelfMirai
2025-12-24 23:05:117916e2f6e47d71fcc0a48bf85d4bce2a61623035bc91eda55f036f1f6482a956elfMirai
2025-12-24 23:05:11959f6557999d6008ef5dd2ff0faf5810a88072fe35202bd993e392f9519a42e1shMirai
2025-12-24 22:58:08d908d2f0b4114165079510ef8fc762c6b6cec60eea6dec514d683f3e67f55680elfGafgyt
2025-12-24 22:58:08e2f49b929531ddce009e62e076af65a97785fe9732012fb13e968ffab3164f43elfMirai