URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/bins/zerarm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3726373
URL: http://213.209.143.64/bins/zerarm6
URL Status:flame Online (spreading malware for 2 days, 11 hours, 41 minutes)
Host: 213.209.143.64
Date added:2025-12-05 18:09:18 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-12-05 18:10:18 UTC to abuse{at}virtualine[dot]org)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-07n/aelf 18edecb267ed8431bcdf583343016bc4a23a14e99f188d0016b3330d50ce37e4n/aMirai
2025-12-05n/aelf 6d4b447aed77888df8f355adbc592f76062b2e600d2ae8816134c0ebe0ac600an/aMirai