URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.80/iran.sparc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3758980
URL: http://130.12.180.80/iran.sparc
URL Status:Offline
Host: 130.12.180.80
Date added:2026-01-16 13:52:11 UTC
Last online:2026-02-06 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2026-01-16 19:37:11 UTC to abuse{at}virtualine[dot]org)
Takedown time:20 days, 20 hours, 37 minutes Bad (down since 2026-02-06 16:14:57 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-02n/aelf d7cf97b36c9707bf20db1c1befb350969e794ac4cd4f851ca920286e65c30eb9n/aMirai
2026-01-31n/aelf 8613991e01ffc1d80cca591aa2b1a2eef4a5426666988a46d21f4e9048db13e2n/aMirai
2026-01-28n/aelf f0d915be65444a278563c7ae7624bb7750a3d43c354dae0736b3f2ab999f25dan/aMirai
2026-01-22n/aelf e5248d246f7f322df12dd428ac74176f0cdb65284bf20d81d648ff9bdd6aaca0n/aMirai
2026-01-20n/aelf 9551b5182889443c7cbd6594f301adcf22ab1803723c33589cc30269207fd999n/aMirai
2026-01-19n/aelf 6b1b16f64c06fe69c2f5fa1f809855628bcf41f00524ac3ee488bfb5598b5a46n/aMirai
2026-01-18n/aelf 433119d6003d2f244033b57e791b1537f4ea5284474064ba140ea2e6722a4060n/aMirai
2026-01-16n/aelf 641b2c3ce92532bd25815191a49ed34efbba7103f35969cd4b9a7ba615e0934bn/aMirai