URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/splarm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739193
URL: http://130.12.180.64/bins/splarm
URL Status:flame Online (spreading malware for 3 days, 19 hours, 57 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:23 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:18 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-25n/aelf 8f6a29ee517a7bb5d9c3db16b8363420c732d8a9d7993da16006a05a6b80c836n/aMirai
2025-12-24n/aelf 540a7e72b2974df7c9f9af4b3ea25dccb7aeba637ff54581ee2ef3e0fd495a46n/aMirai
2025-12-24n/aelf 24da81ab7ddf3bb6220c69daf01d9043e2e5d3b700928864a8c9314b42c2ced4n/aMirai
2025-12-24n/aelf 95b770ac94c945f1e442209fa34e7dd7449469150aace82003e4c76bdccdd4a9n/aMirai
2025-12-22n/aelf ef08459125a017651d2e87b64f1cdc320e46a496126b2b110e8b48b2a3d7f494n/aMirai
2025-12-22n/aelf c34feede8adcef923e40d9347a1075b440e943243f24a0911bce1a5440b52146n/aMirai
2025-12-21n/aelf 784710f0be61df90198f1fa4bfd67e5502dd2a6f4d9a4b025e8d329063597e45n/aMirai
2025-12-21n/aelf d0fa73dfe2c6b4d49c31db63d4424506b62fae9d95a32134d44e4b76cf3745cdn/aMirai