URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.126/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3737793
URL: http://130.12.180.126/arm5
URL Status:flame Online (spreading malware for 26 days, 5 hours, 42 minutes)
Host: 130.12.180.126
Date added:2025-12-20 09:31:13 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-20 09:32:15 UTC to noc{at}pfcloud[dot]io)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-15n/aelf 083e5beea5b26771cee1d513a4d864a85e87a7107f8e0cb8d0e586b5e9de908en/aMirai
2026-01-14n/aelf 5bd461c406516998a763704f0bc7992f79aab37fafeee8bc8ee4f0562493c4fan/aMirai
2025-12-31n/aelf a5202dbe81c29fc2800a3dc5bd72a5968b541ca66af2b08f49aa6dafd94f5236n/aMirai
2025-12-30n/aelf da7cdc7ebe8f9f6f8e1a6b31e63a7ff718c31758bb14418369c4864a7408230an/aMirai
2025-12-26n/aelf 170d09cbbe248453807c571efc93fde9f65f755b4f2a93729bf750e1ee009fb5n/aMirai
2025-12-20n/aelf 371e0cffe2f794224ef69193da697e7d2a8a18b6df44d4f90488797e3630143cn/aMirai