URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/bins/splm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739240
URL: http://130.12.180.64/bins/splm68k
URL Status:flame Online (spreading malware for 3 days, 9 hours, 21 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:02:37 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:03:19 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf af2c1ff89991616654d55cfe8bb43d041462a0980b3e31ab4e1e1ec346a80a79n/aMirai
2025-12-23n/aelf 42b0734f7c690a634bfa4c879517b455c51bf28616d532eeb89227b7f2a735fdn/aMirai
2025-12-22n/aelf 03def24efac35afcb5bff190716f80d32dd7847c4b0940c91e3cabae228d0861n/aMirai
2025-12-21n/aelf 3dd45858083a326da734a9697b80642764b3fd8d5327ed4a9bd473f4acb756b4n/aMirai