URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/jklarm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739149
URL: http://130.12.180.64/bins/jklarm7
URL Status:flame Online (spreading malware for 3 days, 9 hours, 28 minutes)
Host: 130.12.180.64
Date added:2025-12-21 14:54:31 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 14:55:29 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 11debec5c96a5aa87107d64cd434b869e92340cbc5af3f64501dd1952fce2e4an/aMirai
2025-12-24n/aelf e65622d833b92f8f88a2f93ded1dd0a85cb13f2015a24a2a8ca609ccf797ad20n/aMirai
2025-12-23n/aelf 50c0df3bd20a10cb759b83ecce5070ba6390464481af607ea11326b774b482c1n/aMirai
2025-12-22n/aelf b95201e040a89554f506e19c81655dd8a26ddcb5940c0b11d7eacd63f7fd9091n/aMirai
2025-12-21n/aelf f1de0a23ecc35460847304d1da696864c4f028d4ebc61aa4adf3c05c503515d3n/aMirai
2025-12-21n/aelf f90e1a41579de7210c570506f9b4f7267e7a473d8a2b213c4d8ba63c947af70an/aMirai