URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/jklspc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3712977
URL: http://213.209.143.64/jklspc
URL Status:flame Online (spreading malware for 4 days, 7 hours, 55 minutes)
Host: 213.209.143.64
Date added:2025-11-20 17:17:07 UTC
Threat:Malware download Malware download
Reporter: juroots
Abuse complaint sent (?): Yes (2025-11-20 17:18:37 UTC to abuse{at}virtualine[dot]org)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-24n/aelf c022df4a9679d13bca8326b7964d09c2a164c060a15066a9c1099e705731ddcfn/aMirai
2025-11-24n/aelf 6ce2c648564a8ddf2f3490c2f8cf35c072d9b022b22ce6ca727f40a563e34677n/aMirai
2025-11-22n/aelf c5e231a4763e001f813541f8d51b3ef8fc3201b9701802da368a04f24661d85bVirustotal results 46.88%Mirai
2025-11-20n/aelf ebfd963cd7ec7d3bbcef53a8e3733220626a380015859ce785643b76fee643b9Virustotal results 50.00%Mirai