URLhaus Database

You are currently viewing the URLhaus database entry for http://143.20.185.102/windyluvexecutor/executor.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3688219
URL: http://143.20.185.102/windyluvexecutor/executor.arm7
URL Status:flame Online (spreading malware for 24 days, 17 hours, 45 minutes)
Host: 143.20.185.102
Date added:2025-10-26 22:41:10 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-26 22:42:12 UTC to report{at}abuseradar[dot]com)
Tags:arm DEU elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-20n/aelf 9a7ba3d568290f269f71d3d300d72e89cf5136d21eacbbf5c007948ac9b9de7fn/aMirai
2025-11-15n/aelf ce7ea8c1648fcb4720e47f3d08356f74b58dcf4f4d5030f970ffb5a8d5f23385n/aMirai
2025-11-11n/aelf 7e79b7cf010bf03145bdfb619ad049e00fd60e8bbe7b84408bfa3f12147bc7e5Virustotal results 36.07%Mirai
2025-11-08n/aelf a81972bb34f9ec7553fd75929fff125a01b8c53db350e97161e3cd86bd4e9ab4Virustotal results 40.00%Mirai
2025-10-26n/aelf 500ae3fb9582124d5b31c9d19c72cf9dbfe3bb7ed0ce79e6c5953fe3febebfa0n/aMirai