URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.151/data.powerpc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3778447
URL: http://130.12.180.151/data.powerpc
URL Status:flame Online (spreading malware for 2 days, 19 hours, 53 minutes)
Host: 130.12.180.151
Date added:2026-02-15 20:57:06 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-02-16 07:25:15 UTC to abuse{at}virtualine[dot]org)
Tags:elf gafgyt link geofenced mirai link PowerPC ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-18n/aelf 1fad4d651d64d2101e1505feedd6893b1637ae776d8b28ad01ec9119002c6331n/aMirai
2026-02-17n/aelf 3f8b336a91bbd34ea39e692a9f782466f4ee91a445455d6ec77d5cbdbbe3f44cn/aMirai
2026-02-16n/aelf 8f17f85085f91981089860713c6ae572db5bacc4f5338b1c58d06ae1b7bff5e2n/aGafgyt