URLhaus Database

You are currently viewing the URLhaus database entry for http://143.20.185.245/windyluvexecutor/executor.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3717084
URL: http://143.20.185.245/windyluvexecutor/executor.arm
URL Status:flame Online (spreading malware for 1 day, 4 hours, 46 minutes)
Host: 143.20.185.245
Date added:2025-11-26 10:35:10 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-11-26 10:36:17 UTC to report{at}abuseradar[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-27executor.armelf 4f58e8af8f23cb9cf4e646d1d7c4197a3d52863938289c52b053f9a2d1109cddn/aMirai
2025-11-26executor.armelf c2a046ea359426c9d013df98fd05f3210b312b7beea51aef17f121eb806d0d7cVirustotal results 29.23%Mirai