URLhaus Database

You are currently viewing the URLhaus database entry for http://143.20.185.102/windyluvexecutor/executor.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3688223
URL: http://143.20.185.102/windyluvexecutor/executor.arm5
URL Status:flame Online (spreading malware for 24 days, 17 hours, 45 minutes)
Host: 143.20.185.102
Date added:2025-10-26 22:41:10 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-26 22:42:12 UTC to report{at}abuseradar[dot]com)
Tags:arm DEU elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-20n/aelf 776a3aca92abde0e400027d19ed50101e5a568b451f98e7b9a6535d1dcc71f80n/aMirai
2025-11-15n/aelf 8cd3535da95571a635a3237a6442789af1b8f8876c5fc14b085b09b2bc18f21eVirustotal results 29.69%Mirai
2025-11-11n/aelf 6ae758197ef3137fb4934608e5a700776e072a14e343bef6a1fd12e36c801c88Virustotal results 21.67%Mirai
2025-11-08n/aelf f530fc1862dd337e90e7e114b8ce6682934279ed7404cfc9e015082276dda499n/aMirai
2025-10-26n/aelf 8e0d1f78f9ab563a51efcb1a066cffd84913bb6c8782e2788314f68768da19a6n/aMirai