URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/nabppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740300
URL: http://130.12.180.64/nabppc
URL Status:flame Online (spreading malware for 2 days, 7 hours, 48 minutes)
Host: 130.12.180.64
Date added:2025-12-22 16:35:23 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-22 16:36:26 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 77853b50ab4912d7cb438c92c3a5b1034d7dabb0276dbb3115d79a65b0e6340en/aMirai
2025-12-24n/aelf 95fc6a06f974be25bcc7736e4d8ccd7f0321ae2efc265d2e4e3b2594649f6f96n/aMirai
2025-12-23n/aelf 0e9ac7b63fe88b33292a9d4baabf9fc71045c51bf4efad77be1a85a052242e67n/aMirai
2025-12-22n/aelf 3813cfff18dfec74fc578e582ab44c6146019ba4ba7b3a5d7a711ae99963d362n/aMirai