URLhaus Database

You are currently viewing the URLhaus database entry for http://160.30.44.120/neon.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3560374
URL: http://160.30.44.120/neon.x86_64
URL Status:Offline
Host: 160.30.44.120
Date added:2025-06-10 15:54:05 UTC
Last online:2025-07-09 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-06-10 15:55:10 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:28 days, 20 hours, 0 minutes Bad (down since 2025-07-09 11:55:57 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-30n/aelf 92a79801513ef6941ab613b53691339d35bda1a353414009bc9a4a75d4e34b66Virustotal results 40.00%Mirai
2025-06-20n/aelf 4b9c40b0049d3c9b46ce2578579bbd334bfeb12fe4184baf387a1f3ccb952d2bVirustotal results 52.31%Mirai
2025-06-20n/aelf 0749e85bc5e9dd55c48ef5a4d15b16630450663d81087b131c477994161c121cn/aMirai
2025-06-20n/aelf 7590eb8435361c2796db4ab7f80fd890c3d0939ee54d6914d3417c7ead541107n/aMirai
2025-06-20n/aelf 34d705ada75c665494aecd6ffac896940eaf9ddc1c1fe0b0db7c9e0f37d119a2Virustotal results 56.25%Mirai
2025-06-19n/aelf 9ba9f2ba8062309049f14f3a3a8ff50b363cf7a1a1a9b5e30a8ec8ca79c62fdan/aMirai
2025-06-15n/aelf 6fdb01658e57d04b2a32ffd64800bed60e9751b979114b8516b9bbed0bccb32bn/aMirai
2025-06-10n/aelf 80326856be566072ffd98509f60baab38204b77db3b5428dcf7d8f2c69556b73Virustotal results 37.50%Mirai