URLhaus Database

You are currently viewing the URLhaus database entry for http://217.60.195.127/zero.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3894472
URL: http://217.60.195.127/zero.x86_64
URL Status:flame Online (spreading malware for 2 days, 12 hours, 5 minutes)
Host: 217.60.195.127
Date added:2026-07-31 06:54:22 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-07-31 06:55:24 UTC to abuse{at}swissnetwork[dot]io)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-02n/aelf 28a16751269feab605a0df2ace7b0023cfc439947ce9b23ebda0675b88bd4dbdn/aMirai
2026-08-01n/aelf ae06dac1811e2ca5ad7b3e544311a494637e60133decbb04f35d6490e8f0706fn/aMirai
2026-07-31n/aelf 712d6a0e637adfb0a54468a1e5233915b531035429bd390b37663638d90d6e8dn/aMirai
2026-07-31n/aelf 74ecb5e2241b2214f426a3de6aefdd49d3d32df47563d18eb3eaca908149cd00n/aMirai