URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/nabppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3727598
URL: http://213.209.143.64/nabppc
URL Status:flame Online (spreading malware for 3 days, 8 hours, 11 minutes)
Host: 213.209.143.64
Date added:2025-12-06 16:37:10 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-06 16:38:17 UTC to abuse{at}lanedo[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-09n/aelf 2e1b81ee5683d4d6c3250383ca677efb0dd1a9950a394865e94465e1f4e575daVirustotal results 31.75%
2025-12-07n/aelf 31440bd3fc8e4fc3155fed1f9de9dc59295b952939fd71b8012fc8d6545970een/a
2025-12-06n/aelf c08fd5aca4ce694fef14cf8b824db9e5b32da9b6ab157afaa8144f244f899b93Virustotal results 45.16%Mirai