URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/nklmpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739199
URL: http://130.12.180.64/bins/nklmpsl
URL Status:flame Online (spreading malware for 3 days, 14 hours, 14 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:24 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:18 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 8cfb89abd8cbf68cbbc941c099ff1598d87dc5e1031f1b55ab3308ecb8615b58n/aMirai
2025-12-24n/aelf 57b9b4e623d6cd28588e257c6fb89a7218379ed96e1a6c9eaadeba26fe8a6a22n/aMirai
2025-12-23n/aelf 5d3ade4d1a754e949719fbddf7d447c6b967c308f86853f57fc7f7173dd1a2e6n/aMirai
2025-12-21n/aelf c738cdde456aef32551501d9a77e8dbd2f0e8021b463598345e4bc4b609d37aen/aMirai
2025-12-21n/aelf e1bc1faac8c3113f1dd06e4e5053fc85208b9b0facff425e66535050cf49a59cn/aMirai
2025-12-21n/aelf 174a973b574cd9bc3312301611ffe099b2d83595bffa2bfe1cffc6b6564c5702n/aMirai