URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.20:36695/m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3745420
URL: http://130.12.180.20:36695/m68k
URL Status:flame Online (spreading malware for 28 days, 20 hours, 10 minutes)
Host: 130.12.180.20
Date added:2025-12-28 17:21:08 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-12-28 17:22:13 UTC to abuse{at}virtualine[dot]org)
Tags:elf geofenced m68k mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-26n/aelf 4dae9f444d6d484da953f928ac5ea4ddd9c556e54fed41146d5059183d18fa54n/aMirai
2026-01-23n/aelf eb4598d0449b6b5448eb51d5492d0194bc2572a526d424f8aa344fac8cb62e88n/aMirai
2026-01-20n/aelf 7aa15f6b981df851a14780e02980e106cbb0ef75985af1733804e7e034d8c821n/aMirai
2026-01-02n/aelf fe435122d82716e7c7b006d091bfdad9fe4fb22ed8987ac8db3ba89e053251d1n/aMirai
2026-01-01n/aelf 905df6911c97f3622a111ea55c5cd2e433904ec480e4bfa0e1b73d77f3613597n/aMirai
2026-01-01n/aelf bd214eb0c453b8132dd4a901ea5bccbe939f25f6fcdba7ddde9149a2721385dbn/aMirai
2025-12-28n/aelf b041660f92a91d789663cf2b84acb7045c27fc2287283b0dd3bcb4cea0ebb9d8n/aMirai