URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739120
URL: http://130.12.180.64/bins/arm6
URL Status:flame Online (spreading malware for 3 days, 9 hours, 31 minutes)
Host: 130.12.180.64
Date added:2025-12-21 14:53:19 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 14:54:22 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 3e56c62db421fb2d64a341f91b8efcc433c83db5a3dfceebf6e5475419564c2dn/aMirai
2025-12-24n/aelf 93c45488ac8fd7eb5f944ff44505f04d3b67ab6554c31675cf6c478b89ac4cacn/aMirai
2025-12-24n/aelf 5a80382cb6bd8bd5d6c2b0f2ab681b801ea5330ef9b5d1f3bc785339b3faf3d2n/aMirai
2025-12-23n/aelf 64377fa21d4d50db0faf3e423ecca785d621579f973855a2183f949ea054a27bn/aMirai
2025-12-22n/aelf 999bf6d1c12c1aa5abfa6727c2f30587751c340b50842e98bcbe4def70784b73n/aMirai
2025-12-21n/aelf 91f67a01fbe9c03cb7552f354008420098cad785082959e55b5d48a9af50107an/aMirai
2025-12-21n/aelf ac713128acaa4ac62947c969c4fbb1b6c0707c99c1cb81328256f832483768b3n/aMirai