URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/splarm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739139
URL: http://130.12.180.64/bins/splarm7
URL Status:flame Online (spreading malware for 3 days, 9 hours, 30 minutes)
Host: 130.12.180.64
Date added:2025-12-21 14:54:31 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 14:55:29 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 7cc0c7d015dfef9d1917318d0ec9b7cb9d1bb80d8b2b0bff615814bc2a0726ebn/aMirai
2025-12-24n/aelf e65622d833b92f8f88a2f93ded1dd0a85cb13f2015a24a2a8ca609ccf797ad20n/aMirai
2025-12-23n/aelf bb53c80e89c03c910ee91eaa9a6a69b7834b835ee05c290cad9c86af29a821a9n/aMirai
2025-12-21n/aelf d5ec332ace2e37a23b28fc7cf8e5a997f8257c6d48e23b4efa2d6c3e3d6293b5n/aMirai
2025-12-21n/aelf b4a358851f870e634c6c7c00a46b1ecb28f3c96a1d3d76d263c073427b18116en/aMirai
2025-12-21n/aelf ebd1877912ec628403d89fec591218730dfb454d5616e877ed2a70d12edbeeddn/aMirai