URLhaus Database

You are currently viewing the URLhaus database entry for http://130.12.180.106/zermpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3766311
URL: http://130.12.180.106/zermpsl
URL Status:flame Online (spreading malware for 23 days, 7 hours, 43 minutes)
Host: 130.12.180.106
Date added:2026-01-30 20:39:15 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-31 00:09:12 UTC to abuse{at}virtualine[dot]org)
Tags:elf geofenced mips mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-19n/aelf cd1703d5242c6cd2420ba564376f822366b52ea296d1bb005075c9b198a16501n/aMirai
2026-02-16n/aelf b6026c3300e34bfa560ed8fdd6e638cf81c4bf629b3201da31c2135c8ad6f819n/aMirai
2026-02-15n/aelf 68b1f532d9891795738336ee51f5f4eee8c6f2ec8e03980ef00f397828f3c120n/aMirai
2026-02-12n/aelf 2202021d271eea5c2cd82b7c06299da17a51bcaf6e977ebb4bac3cb4ab38a999n/a
2026-02-07n/aelf 9ea5a98cb39e2d3ee06761b61f8bfa690b1736541c17cf5ec5090d3f17cdbbd5n/a
2026-02-06n/aelf 2ff91b157549a434d43d9d9b013a57775c7cea4b98d221273218759a9b0bbbean/aMirai
2026-02-04n/aelf 5655095e0fbcb8f14a0a086f66dd9dceb92e126ee096eeb96c8718bf98481769n/a
2026-02-02n/aelf c27bd5d6ac8115410b857aef6615746145506482f8418bf5e8c3882dc7207db8n/aMirai
2026-01-31n/aelf a67a35781ab666ad5ab6f87baf53b869b87ff7e313a7a0af676af1dece2354can/aMirai