URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/f which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740356
URL: http://130.12.180.64/f
URL Status:flame Online (spreading malware for 1 month, 1 days, 0 hours, 45 minutes)
Host: 130.12.180.64
Date added:2025-12-22 16:36:27 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-22 16:37:20 UTC to abuse{at}virtualine[dot]org)
Tags:mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-21fsh e06319a2a6d0f18a56e46139d3d51a334dbafb491c0c8bbe8f08a504e45dbdb1n/aMirai
2026-01-13fsh 8f6fe24cc25d8f6361f34a27102c04755729510bd5b74d5f03b0899180f8c5ddn/aMirai
2026-01-05fsh d66b9558caa4bbab31fb9de655c289ffa98e26e78dbb3de1932d5fbeff3b7906n/aMirai
2026-01-01fsh 8dc3b44321a22f6851b1c43ca49a4de455169aad6cc1ee694fae092ce2e0394dn/aMirai
2025-12-22fsh 1ec387a244e0d28868d7ccee4398a601717f0609b648e74160eafd4fd7f2feben/aMirai