URLhaus Database

You are currently viewing the URLhaus database entry for http://217.60.195.127/zero.mipsrouter which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3893023
URL: http://217.60.195.127/zero.mipsrouter
URL Status:flame Online (spreading malware for 4 days, 0 hours, 32 minutes)
Host: 217.60.195.127
Date added:2026-07-28 14:43:23 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-07-28 14:44:16 UTC to abuse{at}swissnetwork[dot]io)
Tags:217-60-195-127 elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-01n/aelf d9511387127b4395e716c2bbb6e4baf8b5ed27ea4f557afd1f69174854ba147en/aMirai
2026-07-31n/aelf 8971bc38f11bb873115e0839508cdff8452dc34d993ebaac332e84dad96a45bfn/aMirai
2026-07-30n/aelf e202969e703aa1cffa4932c7dfba8b667e99f8c9cc556497223f5bc08e0756ean/aMirai
2026-07-29n/aelf 4ae8ca363d5dabce54deb29394ba21ca5b5a6d1646d1063c42c453567f40cdden/aMirai
2026-07-29n/aelf a4c8e913b89b45b64ee0a252b106388f28606cc5ac29779bcbad4b8dbb156646n/aMirai
2026-07-28n/aelf ca0828978ee1dd49804366aaf75fda5635b32352dac20e0db89ca102589292fdn/aMirai