URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.119:8080/21.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3821267
URL: http://130.12.180.119:8080/21.exe
URL Status:flame Online (spreading malware for 14 days, 5 hours, 33 minutes)
Host: 130.12.180.119
Date added:2026-04-14 09:38:08 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-04-14 09:39:13 UTC to abuse{at}virtualine[dot]org)
Tags:130-12-180-119-8080 exe OffLoader Tofsee link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-2021.exeexe 345567816147141c9bb71b498cc183cc8bbd33787eec27c83579cc0598348f14n/aTofsee
2026-04-1921.exeexe d890d8e83ddf23c730cfbaa368e61127e15a653fca416e899b1f5115df6bd710n/a Tofsee
2026-04-1621.exeexe f204fee177aa501688820f38a21e3183351a98db83e33763fe6b5774469d4e50n/a OffLoader
2026-04-1421.exeexe 5ec30eee79375992113484eb74be32aa78cbc2ddc1f7d59cd1f06c54cd916d4cn/aTofsee