URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/splm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739416
URL: http://130.12.180.64/splm68k
URL Status:flame Online (spreading malware for 3 days, 8 hours, 24 minutes)
Host: 130.12.180.64
Date added:2025-12-21 15:13:20 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:14:18 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf af2c1ff89991616654d55cfe8bb43d041462a0980b3e31ab4e1e1ec346a80a79n/aMirai
2025-12-24n/aelf faac23322a879028376535adc12f3978c8605d56c0fca5336302e8442f4cccacn/aMirai
2025-12-23n/aelf 42b0734f7c690a634bfa4c879517b455c51bf28616d532eeb89227b7f2a735fdn/aMirai
2025-12-22n/aelf 03def24efac35afcb5bff190716f80d32dd7847c4b0940c91e3cabae228d0861n/aMirai
2025-12-21n/aelf d4d6dd37b0a8eeaef86167568e2056b56883117f5017569f65ad36ee1d07cfcan/aMirai
2025-12-21n/aelf 3dd45858083a326da734a9697b80642764b3fd8d5327ed4a9bd473f4acb756b4n/aMirai