🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.182.77/tplink.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3897933
URL: http://130.12.182.77/tplink.sh
URL Status:Offline
Host: 130.12.182.77
Date added:2026-08-06 13:10:35 UTC
Last online:2026-08-31 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-08-06 13:11:39 UTC to abuse{at}abusehandler[dot]net)
Takedown time:25 days, 8 hours, 48 minutes Bad (down since 2026-08-31 22:00:31 UTC)
Tags:mirai link opendir sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-29tplink.shsh 7596c7cd39c21b53a9057f25150bdbf786fd29d0e3137ef1ad04ea36ddf332b7n/a
2026-08-19tplink.shsh be5aab087b3c0eb65e7ab261f9ae161f5fb3225e54c21b86ee01eff85bec4c2dn/aMirai
2026-08-14tplink.shsh a31041a3d49bad7ffcbc1e49d5e0275e75f3fde7fc43093385aa7d6d9b9ad2b6n/a
2026-08-10tplink.shsh d3b7f99f3d24b21c119e5fdb4114e2fcc9c044569ad8bb2b030bce09152a9d51n/aMirai
2026-08-09tplink.shsh 3320e53b957e9583c55683cea6996f86b52bc31d7600a49d3ce2b7df76ae45e4n/aMirai
2026-08-07tplink.shsh 08b2f8080a69d822cd030695a824bb12b75949d98e810c620daeca70735da1d7n/aMirai
2026-08-06tplink.shsh 1ccd4945da4ede5299542ae4138a10ec6f360e091b82b044b41625d26bafb3a6n/aMirai