URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739170
URL: http://130.12.180.64/arm
URL Status:flame Online (spreading malware for 3 days, 14 hours, 22 minutes)
Host: 130.12.180.64
Date added:2025-12-21 14:54:43 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 14:55:30 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-25n/aelf b9bd8c3bc138f3a2cd136b6224358d2ac7f4a779efe65e5b8c96458e79950e88n/aMirai
2025-12-24n/aelf 54d29b85aa239ea8df3412d49e727b28342ac5ac89ad4eb36b68ea34f7a104d5n/aMirai
2025-12-24n/aelf 95b770ac94c945f1e442209fa34e7dd7449469150aace82003e4c76bdccdd4a9n/aMirai
2025-12-23n/aelf a9de592f001cfcdee2b6c93ae52aedb5967eec5c8039acddd52c7779bfc8ec6en/aMirai
2025-12-22n/aelf 18b7b17079c872f5fec6948e370c4a959e2bd9602e819fa1d23953bb479a5d00n/aMirai
2025-12-21n/aelf b5555015c3fab31248c83cf8078081558887d3cf2d5982cffd3b896161ef3680n/aMirai
2025-12-21n/aelf 1df127cac97ecff975ccdc39b1412068397b948821490910a9c0e3e11114e5f9n/aMirai