URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/zerarm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3726552
URL: http://213.209.143.64/zerarm5
URL Status:Offline
Host: 213.209.143.64
Date added:2025-12-05 18:23:10 UTC
Last online:2025-12-18 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-12-05 18:24:15 UTC to abuse{at}virtualine[dot]org)
Takedown time:12 days, 6 hours, 17 minutes Bad (down since 2025-12-18 00:41:58 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-17n/aelf 11be9259843c96c79c4fc470a75225739fe43edec7d8fe2fccaa26d52851aa92n/aMirai
2025-12-17n/aelf 6bc01f5cf36acfb3bd1f36b221484e2e0f6bf1b2f45d944877fc70d884d1f868n/aMirai
2025-12-16n/aelf dfc1f522341df6a7cc0f13f6c890c95a9e1b094d4466276400592b8e310ac1d9n/aMirai
2025-12-16n/aelf ecaa925caa5e49e06c721d6412db2429e74810fc9b79d00f145331d4982fd52cn/aMirai
2025-12-16n/aelf dd73a42aaa6582d49cab1ddab83e0a7b8e836285ff3b075972e45af8c46b5c7cn/aMirai
2025-12-15n/aelf 94e745e20555fa9afb2587f7a69a4c1fa8d210a114afb2dcda9de5611c9630f6n/aMirai
2025-12-15n/aelf fe4ef43bcf4620a5e59bab713447c2161321cdaf0f9def3371d36a0041a490afn/aMirai
2025-12-14n/aelf 64b3e31cfba21a72c034e1ffe9482a4fb18a3e7d119d6813330aa87d348dd16en/aMirai
2025-12-13n/aelf 8728bebf4405e2d004aa7b2bfb6161c9963987aaf35822cdf4f851ea939bc0c4n/aMirai
2025-12-09n/aelf 93dbbdb9ecd894f4b1a3f0bc9ef773e65ec629e8ef23e481c597c067734a3a1fn/aMirai
2025-12-07n/aelf 233b9a33763cb7c63e71edfd6b8d2634c836874c19bd2875af301a33d67b1e23n/aMirai
2025-12-05n/aelf 959b7dc35d1a13cc2fa6bb76f35ec3aad09225df99b474fcf50f9663aa35711an/aMirai