URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.62/bins/UnHAnaAW.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3639132
URL: http://213.209.143.62/bins/UnHAnaAW.arm7
URL Status:flame Online (spreading malware for 1 month, 18 days, 16 hours, 32 minutes)
Host: 213.209.143.62
Date added:2025-10-02 05:35:22 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-02 05:36:13 UTC to abuse{at}virtualine[dot]org)
Tags:arm elf geofenced mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-11n/aelf 51bb3572999cd4a4b25fd0cc06b061674df3373767c789ceff16b677a2e4bdc5Virustotal results 63.49%Mirai
2025-10-26n/aelf bf0b7a3bab54d71d6ec17e19e603671f36325ba0701499edda0163a35fad3fa7Virustotal results 26.56%Mirai
2025-10-18n/aelf 289d71e0d077e1473836ebbd89a69fcd646c9e860f16c2c63b7abf090d8a4a02Virustotal results 58.97%Mirai
2025-10-08n/aelf 8f89d77bbff6bda4b216b2ec0542640f6671a79026136d47dfc8b45226bc068eVirustotal results 60.94%Mirai
2025-10-02n/aelf 5448ee4408dc315f91588f2db04124aa862abfb2537a9e4c1b97fb05e8fdafe2Virustotal results 64.06%Mirai