URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.2/bins/xnxnxnxnxnxnxnxnpowerpcxnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739933
URL: http://130.12.180.2/bins/xnxnxnxnxnxnxnxnpowerpcxnxn
URL Status:Offline
Host: 130.12.180.2
Date added:2025-12-22 07:00:22 UTC
Last online:2026-01-12 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-12-22 07:01:30 UTC to abuse{at}virtualine[dot]org)
Takedown time:21 days, 8 hours, 8 minutes Bad (down since 2026-01-12 15:09:30 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-10n/aelf 2ebe327cd44fbc466b8f0b8ed5ae5cd9aca1b51006d3850c830fb751179d3179n/aMirai
2026-01-01n/aelf 6ed4750e4b02c209861c253bc6cfec44593308a765363e10818d1241c2abe31an/aMirai
2025-12-31n/aelf 8d845789762cbb7ca027fd2f2189d6fa727d8de92fdbda9e36e2deec13f67acbn/aMirai
2025-12-31n/aelf 8048ef63785893266055a16310b923c8731b4d6e9c51d2baba471a8c3f53de55n/aMirai
2025-12-22n/aelf ba3287ed9914220cf4fcf4dd493c67292c4d1095d9ead5359bc3f38666335b1en/aMirai