URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/nklarm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739197
URL: http://130.12.180.64/bins/nklarm6
URL Status:flame Online (spreading malware for 3 days, 19 hours, 57 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:24 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:18 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-25n/aelf 8d683fb59a9ff9a0a94e4e1205e1c6913526e4daa8fd9e8525687837ba574e9fn/aMirai
2025-12-24n/aelf 940ba63f253c30294eff411219e6b70ee3fe4960d541dadcedc4c48fb191ef8dn/aMirai
2025-12-24n/aelf 32bbec68256cc9ecfb9b1605b91ce72b956d0b962e2aec1721a3c581824331b0n/aMirai
2025-12-22n/aelf 4fd84762899b7f1c0f482d4fa689a8a0e9cd47f80441645c4bd49a66488f079dn/aMirai
2025-12-22n/aelf 13d4ca153f026c57860c660382e667fe59f2c8c45abd7a79751d87532d1d6bd0n/aMirai
2025-12-21n/aelf 5142f74ea28905556509f9a398408d3344934d2c673367dac758d62322d1975an/aMirai
2025-12-21n/aelf e36d2400e7ce8f2fad75a987b9061581b80ae5bc5722dadf5f0383987f6384fcn/aMirai