URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.143.64/nklppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3727603
URL: http://213.209.143.64/nklppc
URL Status:flame Online (spreading malware for 3 days, 8 hours, 32 minutes)
Host: 213.209.143.64
Date added:2025-12-06 16:37:10 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-06 16:38:17 UTC to abuse{at}lanedo[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-09n/aelf 3a79bd0d604993cc0f9405c8df2fceed1e1e6fb921c0841be3472135e02f01d0n/aMirai
2025-12-07n/aelf e2c0880b8c5fc686c395505f35417c2aca45e5b06156e2e3e26bfaff8d9f4614Virustotal results 43.75%Mirai
2025-12-06n/aelf 03649d0f8bdac07babe4624eac2842fffd706ed8b3a16cb3f49ff3c06c6a3d26Virustotal results 50.00%Mirai