URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/zerppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739399
URL: http://130.12.180.64/zerppc
URL Status:flame Online (spreading malware for 24 days, 7 hours, 12 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:13:19 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:14:17 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-12n/aelf 3afebd82b9db2502696ef58094e2119f31b07a8faf76d501d803dcb61e3c467dn/aMirai
2026-01-12n/aelf 1ccb8cbf82c33555ef8cfcea04ac64d61aa2aabbb60cdba8009e1388b28bbb47n/aMirai
2026-01-11n/aelf 06ed8a292ad3bd18c5983b255bf7c77bc431bf7a01a1abcf4931ae03337e838an/aMirai
2026-01-11n/aelf d5a10665c3367a9522e1a0dfa8c3a4859d2f63b66178e27b00a20826a0468eb6n/aMirai
2026-01-05n/aelf bbd94eb805091a9d64ede05cf8b5199bf90cf0d80dc5dfd3a0dc01b29353f14bn/aMirai
2026-01-01n/aelf bc28983d44c91d3062f924f80cc99045d127cc9967125aa8be5c85dde32edafan/aMirai
2025-12-24n/aelf 95fc6a06f974be25bcc7736e4d8ccd7f0321ae2efc265d2e4e3b2594649f6f96n/aMirai
2025-12-24n/aelf a43163337ade536f2bf51a2ae5b9bea00b22a8da68deed599d96df8426ed3359n/aMirai
2025-12-24n/aelf ca271276fc9a2d234462d4cdd9cb47980bf43089f1aa70494342585301daea9dn/aMirai
2025-12-21n/aelf eeeebb5aeb2e8e0f5ac9d5baed9ab50540357fab439fb30c9dbf5f2a3e67cedcn/aMirai
2025-12-21n/aelf 4336f2ee02e9db6bcd78cac01c923518a50447a9e9a00f58d0442a4df82f9685n/aMirai