URLhaus Database

You are currently viewing the URLhaus database entry for http://144.172.109.62/windyloveyou/windy.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3681128
URL: http://144.172.109.62/windyloveyou/windy.x86_64
URL Status:Offline
Host: 144.172.109.62
Date added:2025-10-18 16:06:11 UTC
Last online:2025-10-20 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-10-18 16:07:16 UTC to abuse-reports{at}cloudzy[dot]com)
Takedown time:1 day, 12 hours, 57 minutes Poor (down since 2025-10-20 05:05:02 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-19n/aelf f57fc99d3e88e27f631d671334ccc10003f7157cf2fd9cc8ebb9e4b9d29d7426Virustotal results 40.00%Mirai
2025-10-19n/aelf b06536dcc200ca268ec79fd8b4b57c779a8b5e4a223a39497ca4fc6d77ab20c5Virustotal results 25.45%Mirai
2025-10-18n/aelf 8bc21a868d10a8cb1b9a2130d1ca2f3b8e6bf80d6d48bc436c9930c944a1359dn/aMirai