URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/zerm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739187
URL: http://130.12.180.64/bins/zerm68k
URL Status:flame Online (spreading malware for 3 days, 7 hours, 3 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:22 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:17 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf d29d2e4446cd075aabd578393dccd3a9a2d5130fe435b90ca6956fa291256a6en/aMirai
2025-12-24n/aelf 7c6cc7153db4e2b06f102aa06cab68d020a8dc58cc275b421c4141c160008955n/aMirai
2025-12-22n/aelf 894e31da072638bcf6a6d399a4efd0c62abfcf1007746884838099d0274b34abn/aMirai
2025-12-21n/aelf c6ba8a7005cec730afefc2f69865512c986bf08fd201345c83ced08ec8df4ef3n/aMirai