URLhaus Database

You are currently viewing the URLhaus database entry for http://23.140.244.57/x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3829389
URL: http://23.140.244.57/x86_64
URL Status:flame Online (spreading malware for 1 month, 4 days, 6 hours, 36 minutes)
Host: 23.140.244.57
Date added:2026-04-23 05:25:17 UTC
Threat:Malware download Malware download
Reporter: NoahB
Abuse complaint sent (?): Yes (2026-04-23 05:26:17 UTC to James{at}22ovz[dot]com)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-23n/aelf 50f9f1d908d0515151fb87663b2a0d5a333034764f18f1d4502508bf92a3aaa0n/aMirai
2026-05-23n/aelf cebd1030186a4102b695c958ef31aa9a7a27505dd6ffa70a7e9284fab975eebdn/aMirai
2026-05-23n/aelf d96ad13231f7dba68647498631c9131f8e261da9dffe73b1efbd729fdeb9a756n/aMirai
2026-04-23n/aelf b95415f0036409418073ef58d81ace9a00cfae0f942a4f7e9e90b2b54764a554n/aMirai