URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.126/tplink.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3738802
URL: http://130.12.180.126/tplink.sh
URL Status:flame Online (spreading malware for 4 days, 13 hours, 13 minutes)
Host: 130.12.180.126
Date added:2025-12-21 09:28:30 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 09:29:25 UTC to abuse{at}virtualine[dot]org)
Tags:censys mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-22tplink.shsh c015ba68be279cdaccf27c7b7a28edc18e3e02d9b7509fbdc4e5f79eda2fe518n/aMirai
2025-12-22tplink.shsh 7bf6ce55eae813ebcd86cfaecf9afbacfb0de98ba28d1949d835eccbb10b28c3n/aMirai
2025-12-21tplink.shsh a424a82841f3804076601f67f5b79f362994ed79ac70bb669f7c8d758af9a7aen/aMirai
2025-12-21tplink.shsh cd7fa740d0adf255a3425e702ec1ef2521dacb871079773d90463c918a26fcd9n/aMirai