URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/zermips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739219
URL: http://130.12.180.64/bins/zermips
URL Status:flame Online (spreading malware for 3 days, 9 hours, 22 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:25 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:18 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf c1521d4634f342814ccbc2abe4fa8634b43af06633d1733d61b6b856a01fa48dn/aMirai
2025-12-21n/aelf 2f5a2f3a9853061e89102a0d41e6027c3e9cc94d7a2d4ee91663e17768cee255n/aMirai
2025-12-21n/aelf 0fc47e51b950d0c9feef18299d94898980682002b327e5604c86c6ea9ba51ebcn/aMirai