URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.22/file/data.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3765771
URL: http://130.12.180.22/file/data.mips
URL Status:Offline
Host: 130.12.180.22
Date added:2026-01-29 20:12:13 UTC
Last online:2026-02-01 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-29 20:13:15 UTC to abuse{at}virtualine[dot]org)
Takedown time:2 days, 10 hours, 25 minutes Poor (down since 2026-02-01 06:38:19 UTC)
Tags:elf geofenced mips mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-01data.mipself 3ebb0c37d9241d0d7b1123adf2536f74bfbfbd5910f26d7eb716df7ac6e2f824n/aMirai
2026-01-31data.mipself 6b7c5899cd5e9940e7e55096de15877a4633a4588f311b2f6c6afe1c77c8a67en/a
2026-01-31data.mipself 4c05e52c7ab0f90efc6fb4a57d7703fdadf6a8fa0fa021870826f8f86a51a394n/aMirai
2026-01-30data.mipself fdb55d8a6b874cf6268fa8b8f0ad1d560deafee1892e6aa49b9470dbed37f5c7n/aMirai
2026-01-29data.mipself ce985bb3687be868da7ac9681bb48be74940afb02b721d43b83becd2ec8fbdean/aMirai