URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/zerarm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3726573
URL: http://213.209.143.64/zerarm
URL Status:Offline
Host: 213.209.143.64
Date added:2025-12-05 18:23:17 UTC
Last online:2025-12-18 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-12-05 18:24:15 UTC to abuse{at}virtualine[dot]org)
Takedown time:12 days, 14 hours, 39 minutes Bad (down since 2025-12-18 09:03:47 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-17n/aelf b3327565abb469b5e72ec0a7507534510ccc60acb002cb2b283735323a112420n/aMirai
2025-12-17n/aelf b7d4af91ac87fc5282813754910c95ffaf42a19eaef85989a0724884c56b95fbn/aMirai
2025-12-16n/aelf cd277f27c23ce0b6a06cc53cdd1169193050118d94f87b010898636a9723e496n/aMirai
2025-12-16n/aelf 3b35b376346a517fccad7544f82131b179bc858f21b47b9571e73c27a382239en/aMirai
2025-12-15n/aelf 43cee282a57a4049abb8961961bd4a50593214e99549f0fde430065c6e90d883n/aMirai
2025-12-15n/aelf 36eee49c8103a59b7c640b0bd40e06ba240aa6e387ca542df000da6caed83e64n/aMirai
2025-12-14n/aelf b3690b2b74aae1fc239d32b5ea4ec9086ba4cd766e887eb797ffe145d853bbdfn/aMirai
2025-12-14n/aelf a6e13bed019313c116d094bfc27e8dab6b2c00b224f5ac21392daa57904fd5d2n/aMirai
2025-12-14n/aelf d47a629998e47321f4260ec6bb953c6a64a0ea7e1fa3281612b29b6837871b41n/aMirai
2025-12-09n/aelf 1e31c5588a1085d79c6b656da8e6797778f7bb5c739daa9a9dcaa8df4121f725n/aMirai
2025-12-07n/aelf b1fc3983f0bc36b499b62f9259598228ea731bf8f42662d160d60a1d3927a2c6n/aMirai
2025-12-05n/aelf e40d5e1ae2f59cf1fd8c0399dd6c1dc7f8650d02b2fa9c49defe62fb5d68669dn/aMirai