URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/zerspc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3726580
URL: http://213.209.143.64/zerspc
URL Status:flame Online (spreading malware for 4 days, 2 hours, 47 minutes)
Host: 213.209.143.64
Date added:2025-12-05 18:23:19 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-12-05 18:24:15 UTC to abuse{at}virtualine[dot]org)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-09n/aelf 9ad6c1f6c898ab2730a68f8c24bb4f686e35fa5cd01c94473f2b62b6c2772e30n/aMirai
2025-12-07n/aelf 6496c61113866790377cfe12852de2281442a0a39857e7fb9081dce52540fc59n/a
2025-12-05n/aelf 58047ae1e9f63fefde5845b580d3a98486d34b6d63279d6ae5170c0f02587d6cn/aMirai