URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/nabmpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739222
URL: http://130.12.180.64/bins/nabmpsl
URL Status:flame Online (spreading malware for 3 days, 19 hours, 57 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:25 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:19 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-25n/aelf cd77215ddcec0dc7e6edba44b8f8b17e0e4ef1d2b5582463e67c116bfbbab5fdn/aMirai
2025-12-24n/aelf eda9aa3b28cf93cc277ae358e63d90d29396a525600ce88a58ca1386889a3feen/aMirai
2025-12-22n/aelf 83c01118d8284ad15d850d6ae0f1dbb8bae57b75dddb02be0fc1fa1f9cb85576n/aMirai
2025-12-22n/aelf 150d3385013eb3f5cb651780e632d1bf3aff388acbaa091358a14da6d7f542dan/aMirai
2025-12-21n/aelf 27ab3c095b97a2206d5d0af1db0a53a623c906623df762432944cb08d15b19b9n/aMirai
2025-12-21n/aelf b493fd982c2231468c037262657fa521a592140f0824d90466a71ba0f18baf9fn/aMirai