URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.16/bins/xnxnxnxnxnxnxnxnmicroblazexnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739950
URL: http://130.12.180.16/bins/xnxnxnxnxnxnxnxnmicroblazexnxn
URL Status:flame Online (spreading malware for 2 days, 15 hours, 5 minutes)
Host: 130.12.180.16
Date added:2025-12-22 07:00:22 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-12-22 07:01:36 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf b86bc12632d541d7a70a0b379deca5e6bce7042180a44e08d155835d0b01471dn/aMirai
2025-12-23n/aelf 0cd41af39b4cb9501b2a2e606d8be3c653e930debec2e69ea81f260f70fd6bdcn/aMirai
2025-12-23n/aelf f7f62a496442ac53a59fe117e9cda1375ac656bb6e3d1b77af5954e2267b0937n/aMirai
2025-12-22n/aelf 462cc9496008db5d12d32b7a1691abcd769acc5b7c6b8df9ebc59d46553f89e0n/aMirai