URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/zerppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739221
URL: http://130.12.180.64/bins/zerppc
URL Status:flame Online (spreading malware for 3 days, 14 hours, 14 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:25 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:19 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf a43163337ade536f2bf51a2ae5b9bea00b22a8da68deed599d96df8426ed3359n/aMirai
2025-12-24n/aelf 95fc6a06f974be25bcc7736e4d8ccd7f0321ae2efc265d2e4e3b2594649f6f96n/aMirai
2025-12-21n/aelf eeeebb5aeb2e8e0f5ac9d5baed9ab50540357fab439fb30c9dbf5f2a3e67cedcn/aMirai
2025-12-21n/aelf 4336f2ee02e9db6bcd78cac01c923518a50447a9e9a00f58d0442a4df82f9685n/aMirai