URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3700422
URL: http://213.209.143.64/sh4
URL Status:flame Online (spreading malware for 11 days, 1 hours, 56 minutes)
Host: 213.209.143.64
Date added:2025-11-08 09:45:14 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-11-08 09:46:11 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18n/aelf d3e1ab0f38ed2d29a85128ad40e0577aabab12d6277a4781a80a97daaccbfff0n/aMirai
2025-11-18n/aelf 950f763d1f1d2c35888695953a6dd06ca74ee43ae069bb0ddcb0765081de3784n/aMirai
2025-11-16n/aelf 99104fd8e37481e2bebd791a608955475440a78377e7bdf26edf122e62edb60dn/aMirai
2025-11-16n/aelf fdf483f9a4489655ac803d2ff23294da3eef6bab35340298dac2d7f3889c7724n/aMirai
2025-11-15n/aelf 8aaee1078e9cfb6e1b002aff838a2b98e34d19bfc601d97ee7fa6868386dc2e2n/aMirai
2025-11-15n/aelf badb2d9863edde0ec0af9d7a4139aca52713540f53408decff2f0a6ef6209d62n/aMirai
2025-11-14n/aelf f5b7ca0b46638e239a0bac1172d04c5389c0dac20d4ea633d3ee7bcea235c5d5n/aMirai
2025-11-13n/aelf 14824e0b1682450aaee6fd0d8ea5c9ea950e2d67984d94f590c28c016c2eb1d2n/aMirai
2025-11-11n/aelf 5fbf27bb64ae8e7a03a163fff0a6f0b163f97d7d7327b5f64c0df5bd7470e1bcn/aMirai
2025-11-10n/aelf 317f536f23f17d3391b06650ad9b00fbae1865f264729d50b40d4db5c504c8f0n/aMirai
2025-11-09n/aelf a0b0d8a31f843cd8b071bf2e794fadc9f4175c95ff0c6f2997f302c9e89dae74n/aMirai
2025-11-09n/aelf c18deef077228c5cd8fd1fa44761e5e9c798e007f0784873edaddbbffbf46507n/aMirai
2025-11-09n/aelf e53db4b13ee7c2553fab624257e579295d1e155f23984cea31acde01b0e1b115n/aMirai
2025-11-08n/aelf f094dbfb09c537305457c83d9bcb568cff484fd30d9060c8d85941cb3f91827eVirustotal results 59.38%Mirai