URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/jklarm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739229
URL: http://130.12.180.64/bins/jklarm5
URL Status:flame Online (spreading malware for 3 days, 12 hours, 50 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:31 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:19 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf f3d791ee79cea878f3e032c127fc38da0ff51b26932ebd376a98dbd9f0d74d5an/aMirai
2025-12-24n/aelf e23e229afd3252fcd523e130b503f35fffb7bce0e1e090145122a9510567a405n/aMirai
2025-12-22n/aelf ce8f836fb5f1824ccd36e80792b35673d7517c2720d57736e2b66222ff5d453en/aMirai
2025-12-21n/aelf 8505dfff2f15c5da8d2c6a87bed522591933ca8af938cc8beecd000b01009facn/aMirai
2025-12-21n/aelf daabf21dbeaa9aac310ddf1bb72fad35b4b64b3250dc9b0dca15c7e11d0824b3n/aMirai
2025-12-21n/aelf f95187f0489f498c932ec698245e824170ca97d28405bf984fd89e9bb8488ff6n/aMirai