URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.64/nabarm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740307
URL: http://130.12.180.64/nabarm
URL Status:flame Online (spreading malware for 2 days, 11 hours, 17 minutes)
Host: 130.12.180.64
Date added:2025-12-22 16:35:23 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-22 16:36:26 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf e47c0652d991b9f96f1da6b9ea41beb032fa234a32497f43d9c3578e658cdc0bn/aMirai
2025-12-24n/aelf 95b770ac94c945f1e442209fa34e7dd7449469150aace82003e4c76bdccdd4a9n/aMirai
2025-12-23n/aelf 0fe54fda91ce051b9f0557b06e6e5824f2fefa4ac54876c0f25475575ad22eeen/aMirai
2025-12-22n/aelf 92672b0ae6d01414680a6361ff8567f96e8ac8085dd7e4f686ea929edeb362cbn/aMirai