URLhaus Database

You are currently viewing the URLhaus database entry for http://143.20.185.102/windyluvexecutor/executor.arm64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3688220
URL: http://143.20.185.102/windyluvexecutor/executor.arm64
URL Status:flame Online (spreading malware for 24 days, 17 hours, 44 minutes)
Host: 143.20.185.102
Date added:2025-10-26 22:41:10 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-26 22:42:12 UTC to report{at}abuseradar[dot]com)
Tags:arm DEU elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-20n/aelf 23fa2fff1c665ea79f63f820182f2f871fac24f5ea863884620a74b15b1d7cf4n/a
2025-11-20n/aelf 5983a38ea284410f772ed1e012c667d40f9bd9d6024becb7a2286a821d38b06bn/a
2025-11-15n/aelf 148ddb73e5415fcb6564679c37c9361615d6d9c1650a1060e076b25ce28fc1d2n/aMirai
2025-11-11n/aelf 69121b5f21dc54a12a7dd44388db6e56844735564bc327572c04f4c76333cfb4Virustotal results 18.46%Mirai
2025-11-08n/aelf 018bbbca5717f4c38f47f152f6b6a49cdd472738cfcffac67368c1105514aa8cn/aMirai
2025-10-26n/aelf 22cdead66c15bf3eff550429b692c70be0e1741f2522d8e174e81187d57a6512n/aMirai