URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.16/bins/xnxnxnxnxnxnxnxnloongarch64xnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739937
URL: http://130.12.180.16/bins/xnxnxnxnxnxnxnxnloongarch64xnxn
URL Status:flame Online (spreading malware for 2 days, 15 hours, 5 minutes)
Host: 130.12.180.16
Date added:2025-12-22 07:00:22 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-12-22 07:01:35 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf a0c7516bb1f9d98bf2632d893599f8a75478e676edc33229b2c72fcc4c80a779n/aMirai
2025-12-23n/aelf 821f3e123512cb605f7da540cfc7cc646d8e2ddfe3253496133131157d653a03n/aMirai
2025-12-23n/aelf 927d5ac1289b95e77e24f168bae4f535f8329828b0489e09f89f1e63ed0b5a21n/aMirai
2025-12-22n/aelf 10ddabc05fe89e6a9ecc5365944ab5859cfeeac4104f945665b4ea87a5a23028n/aMirai