URLhaus Database

You are currently viewing the URLhaus database entry for http://89.144.20.51/bins/UnHAnaAW.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3627104
URL: http://89.144.20.51/bins/UnHAnaAW.ppc
URL Status:Offline
Host: 89.144.20.51
Date added:2025-09-19 17:26:16 UTC
Last online:2025-10-20 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-19 17:27:08 UTC to abuse{at}ghostnet[dot]de)
Takedown time:1 month, 1 days, 5 hours, 31 minutes Bad (down since 2025-10-20 22:58:13 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-09UnHAnaAW.ppcelf 8986d574f66c38aa730786281cd37fa332b6bc7834eaed64f060a386f79cb5c0Virustotal results 56.25%Mirai
2025-10-04UnHAnaAW.ppcelf 4a02f138a94dca23cd2467d088ccf74e64b33eec73fa393bb37cf6234b41474fVirustotal results 56.25%Mirai
2025-09-19UnHAnaAW.ppcelf 8db6aad767475b76f0069fa10985f741b7fb297e0a736c9431f12cddc4ec5b2eVirustotal results 67.19%Mirai