URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/zerarm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3739421
URL: http://130.12.180.64/zerarm5
URL Status:Offline
Host: 130.12.180.64
Date added:2025-12-21 15:13:20 UTC
Last online:2026-01-15 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-21 15:14:18 UTC to abuse{at}virtualine[dot]org)
Takedown time:25 days, 5 hours, 9 minutes Bad (down since 2026-01-15 20:24:12 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-12n/aelf eb0306d24388ba1c88e8ca35cdfda29e28887358f63c6bdc447596657e94dafcn/aMirai
2026-01-12n/aelf 19932b64a799a21266a683aa546896591dcfadfe10c00b17480d36262c1aac77n/aMirai
2026-01-12n/aelf ef27007b9363316d7a94eb900524e781344ab4e375288b171e446c5b297867f1n/aMirai
2026-01-11n/aelf 73139842100847e150ed6b7c08aada5f748d3c890e45b6d38058046ac3e556e1n/aMirai
2026-01-11n/aelf 6839664253f1433ee86597568d67fe960870480f1592014f6818f00f53ea8c22n/aMirai
2026-01-11n/aelf 756b22b5f5111727a484edd0a3b610c39396fd5b8c078cd9d25d6f72cbd720e6n/aMirai
2026-01-06n/aelf f8b55eb873faf9daf14bbddc6d890d9ad8cdcd1b4719f57d4dd12c622048e96bn/aMirai
2026-01-01n/aelf 8f44f026e43ac0687948f34f3d39cf9de3c1320ae3dcc8d49d42106f4684c280n/aMirai
2025-12-24n/aelf 495e5c829f5efc65b49aea5b6fe0e0660853ce084e3f8d600d530e3d7ca4fe04n/aMirai
2025-12-24n/aelf e23e229afd3252fcd523e130b503f35fffb7bce0e1e090145122a9510567a405n/aMirai
2025-12-21n/aelf 7bd2924ecc2c70b802880e00c3be4ed81f888870e2e5ac8dcf593da9d0745568n/aMirai
2025-12-21n/aelf dc4a700f935dd717813708581615f6f11339a75d997b63150f13b53c021e4529n/aMirai