URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/nklmips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739224
URL: http://130.12.180.64/bins/nklmips
URL Status:flame Online (spreading malware for 3 days, 9 hours, 22 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:25 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:19 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf e59658cfbe3d46d78e04e21093597513aba8b9540d83883b41a00979a92befa0n/aMirai
2025-12-24n/aelf e93cc7028328410bdcd0f1d3f77c07b344d2bea0188a0dab6c43decfff1ce551n/aMirai
2025-12-23n/aelf 203c418e5ef79e268ccc27f57c8c4a464132b72fe9d092d3464bcbf9dd6b23c6n/aMirai
2025-12-22n/aelf e293f15bf6d3ae6a6de42b94d0d9ad72e871d96faad67ddcc2cc32495112117bn/aMirai
2025-12-21n/aelf 82053e159596d5d7df81c433efdb3f24b04e01f2d1d55038231c326ee1336850n/aMirai
2025-12-21n/aelf ee7f15a7919dcdfd3dc0e5ca0aa1a5a3c19c6a4d4a797746d23f105ea1e6bbf8n/aMirai