URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.132/bb/arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3759643
URL: http://130.12.180.132/bb/arm5
URL Status:flame Online (spreading malware for 25 days, 3 hours, 48 minutes)
Host: 130.12.180.132
Date added:2026-01-18 02:26:08 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-18 02:27:11 UTC to abuse{at}virtualine[dot]org)
Tags:arm elf geofenced mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-10n/aelf 9b15b37d8442f3e1db5bcae60d87425419f1e817322cdd2d0ab5e8fbac772bd4n/a
2026-02-05n/aelf df733c3ed91b39beb5e8dc602e98e80844c18087ed86d2fe8f0909fffc413041n/a
2026-02-05n/aelf 3121147a7f6bfa6882cac34325fe2fe50c62e6548f1ea8b4ad859eecdf13d46en/a
2026-02-03n/aelf 28d5b45b374a60192159fd0c528f516f1701742c99db48c5a353e14bd46a345an/a
2026-01-24n/aelf 8dc7943e1bb9e44c0d1aae6db96a2cae016c69272aa1533aabdd29431bd70d1dn/a
2026-01-18n/aelf d8dfd517ae77d892702c59bae3cda16824667f19891fc91d5e9752e5664a3e59n/a
2026-01-18n/aelf d65f7c36cabc35afb3fb2bed4288880e198a1c3a014eb5ca3b6d45ec0b6e266cn/aMirai