URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739413
URL: http://130.12.180.64/arm5
URL Status:flame Online (spreading malware for 3 days, 9 hours, 10 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:13:20 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:14:17 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf f3d791ee79cea878f3e032c127fc38da0ff51b26932ebd376a98dbd9f0d74d5an/aMirai
2025-12-24n/aelf e52a46110a291211e550fc1ed4ee875ca35ae13ce54712cb2079796bf5e35d83n/aMirai
2025-12-24n/aelf e23e229afd3252fcd523e130b503f35fffb7bce0e1e090145122a9510567a405n/aMirai
2025-12-22n/aelf ce8f836fb5f1824ccd36e80792b35673d7517c2720d57736e2b66222ff5d453en/aMirai
2025-12-22n/aelf 8505dfff2f15c5da8d2c6a87bed522591933ca8af938cc8beecd000b01009facn/aMirai
2025-12-21n/aelf f95187f0489f498c932ec698245e824170ca97d28405bf984fd89e9bb8488ff6n/aMirai