URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.20:36695/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3745419
URL: http://130.12.180.20:36695/mips
URL Status:Offline
Host: 130.12.180.20
Date added:2025-12-28 17:21:08 UTC
Last online:2026-01-25 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-12-28 17:22:13 UTC to abuse{at}virtualine[dot]org)
Takedown time:27 days, 22 hours, 35 minutes Bad (down since 2026-01-25 15:57:49 UTC)
Tags:elf gafgyt link geofenced mips ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-23n/aelf b3fa2e6dfee9d9ab9ddd0f5ee6f177f25d38ef63740d024506dc68c28413be2dn/aGafgyt
2026-01-20n/aelf 41bac7736e8953e15879a3684196047db9a6522b7dc2815b94ad6c5257ce6043n/aGafgyt
2026-01-08n/aelf 53e7b5419dd8edadced6baf1bbe72316b49eb48b11c1af1d70888fc63ff1d270n/a
2026-01-02n/aelf 82403f351fd24edcf52a763132f75e235c5ddcfe7756f1a787201c923999f311n/aGafgyt
2026-01-01n/aelf 9fb38903e7ede7f90e91269046033fecf669fd65dd2071dc0228f99886d040e0n/aGafgyt
2025-12-28n/aelf d908d2f0b4114165079510ef8fc762c6b6cec60eea6dec514d683f3e67f55680n/aGafgyt