URLhaus Database

You are currently viewing the URLhaus database entry for http://143.20.185.225/dl.php?t=0101011001000010010011110101010001001100010011010100000101001111&arch=acppid which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3806421
URL: http://143.20.185.225/dl.php?t=0101011001000010010011110101010001001100010011010100000101001111&arch=acppid
URL Status:flame Online (spreading malware for 16 hours, 4 minutes)
Host: 143.20.185.225
Date added:2026-03-27 15:36:21 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-03-27 15:37:11 UTC to report{at}abuseradar[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-28acppidelf 84783a9fc4a17cdb2e679ce3c4b13507450b5d35e46ccb59e17e6b8972d3a638n/aMirai
2026-03-27acppidelf f6e66112249f33a9d60e50cd21122e6866e1a699764aab84b04551e40ea91622n/aMirai