URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.22/file/data.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3765767
URL: http://130.12.180.22/file/data.arm7
URL Status:Offline
Host: 130.12.180.22
Date added:2026-01-29 20:12:10 UTC
Last online:2026-02-01 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-29 20:13:14 UTC to abuse{at}virtualine[dot]org)
Takedown time:2 days, 15 hours, 34 minutes Poor (down since 2026-02-01 11:47:42 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-01n/aelf 4989ceb2ffe2ca5084f9f70aafc025a020e3aa6aae79aec6f08ffee43ba88a6an/aMirai
2026-01-31n/aelf c6e28aa60c4e9a85f248a8ee4763efa357a015215a1216226cebffbd7a154043n/aMirai
2026-01-31n/aelf 6bd17beb9125a37a0130ca3d3707eec2ff5310693302f1d4b742294c4d74e018n/aMirai
2026-01-31n/aelf 6cf62ebfc854988b9443a0648bd7af190737a218ddb6883abb48f6eb6fabf518n/aMirai
2026-01-30n/aelf 3d0a0d90f1d95482a657c9da89f01904347c4fda4f7d0e39782438e60a7dec96n/aMirai
2026-01-29n/aelf ab73efe190dd5dabc1adfc57195dcae5b4f119e0ed5cee7895e4186ec23bb092n/aMirai