URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/splx86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3726305
URL: http://213.209.143.64/splx86
URL Status:flame Online (spreading malware for 4 days, 7 hours, 34 minutes)
Host: 213.209.143.64
Date added:2025-12-05 18:07:32 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-05 18:08:13 UTC to abuse{at}virtualine[dot]org)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-09n/aelf 1fc74d3de12213562ead46a8518fbcbf7b95e37ac583850434a63eb46ceaef7cVirustotal results 35.94%
2025-12-07n/aelf 6fac75b407df3ab3700d15c5b3065228db4c6ebc93aac9958c525f079e4e552eVirustotal results 35.38%Mirai
2025-12-05n/aelf 95d9062cb24c84dd10bd70c563b14830b58d55a2508a553bb9d41b0cfd0720fen/aMirai