URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/jklarm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739232
URL: http://130.12.180.64/bins/jklarm
URL Status:flame Online (spreading malware for 3 days, 9 hours, 20 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:37 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:19 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 6e8b462a2b658ab9ab1e6c2218b3c7f047419ffc3da18164d1389cbb737ec9d1n/a
2025-12-24n/aelf 95b770ac94c945f1e442209fa34e7dd7449469150aace82003e4c76bdccdd4a9n/aMirai
2025-12-23n/aelf a9de592f001cfcdee2b6c93ae52aedb5967eec5c8039acddd52c7779bfc8ec6en/aMirai
2025-12-22n/aelf 18b7b17079c872f5fec6948e370c4a959e2bd9602e819fa1d23953bb479a5d00n/aMirai
2025-12-21n/aelf b5555015c3fab31248c83cf8078081558887d3cf2d5982cffd3b896161ef3680n/aMirai
2025-12-21n/aelf 1df127cac97ecff975ccdc39b1412068397b948821490910a9c0e3e11114e5f9n/aMirai