URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/splarm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739238
URL: http://130.12.180.64/bins/splarm6
URL Status:flame Online (spreading malware for 3 days, 19 hours, 57 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:37 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:19 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-25n/aelf 04c3531d541962af0877e71affbce5ab8fd9909d4fba6875c5007736469a5c1bn/aMirai
2025-12-24n/aelf fa62bcbb4cff0013ab416aaa10c8fe9b2c3beb731db15f27eafba9f81d761343n/aMirai
2025-12-24n/aelf 749530dab7eecafd4f1f7d3b63bf1c0ccf2c0ed95ae73cc6702794f640c0116an/aMirai
2025-12-23n/aelf 7acbab1fa1aa1ea342e5594a41423a529d656fd3aaf933fdaf8d687d1099146bn/aMirai
2025-12-21n/aelf df133fd5eca8b3e3deeb09309bb7e8e7757098ef5ab2fbf305df496cb94d7d92n/aMirai
2025-12-21n/aelf 9aaabd9fe5657b63f74af8a3560db6a700260513f92a88e171f98f8c4cbfeed4n/aMirai
2025-12-21n/aelf bc8e090af02223041507c811baf2d718101317807f87bf13fc12bc99dc6e460fn/aMirai