URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/jklarm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3738855
URL: http://130.12.180.64/jklarm7
URL Status:flame Online (spreading malware for 3 days, 10 hours, 59 minutes)
Host: 130.12.180.64
Date added:2025-12-21 09:33:11 UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-12-21 09:34:18 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf e16b97b4df6f3316c798b571ff21c0e70b59d3e43d46fa7704fcdc0cebcbe433n/aMirai
2025-12-24n/aelf e65622d833b92f8f88a2f93ded1dd0a85cb13f2015a24a2a8ca609ccf797ad20n/aMirai
2025-12-22n/aelf 50c0df3bd20a10cb759b83ecce5070ba6390464481af607ea11326b774b482c1n/aMirai
2025-12-22n/aelf b95201e040a89554f506e19c81655dd8a26ddcb5940c0b11d7eacd63f7fd9091n/aMirai
2025-12-21n/aelf f1de0a23ecc35460847304d1da696864c4f028d4ebc61aa4adf3c05c503515d3n/aMirai
2025-12-21n/aelf 64fcab57c878f909ecbefdb13bc62c66db16a4b0e858f723844a70019a913d6bn/aMirai