URLhaus Database

You are currently viewing the URLhaus database entry for http://185.142.53.233/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3491466
URL: http://185.142.53.233/mips
URL Status:Offline
Host: 185.142.53.233
Date added:2025-03-26 19:46:04 UTC
Last online:2025-07-09 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2025-03-26 19:47:06 UTC to abuse{at}fiberway[dot]fr)
Takedown time:3 months, 15 days, 1 hours, 42 minutes Bad (down since 2025-07-09 21:29:33 UTC)
Tags:ddos elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-06n/aelf 63e5d4c2ac320aa49bfc1c23e1a253c00ec5e51b4b64f0fb304c34f4d0a6fa56n/aGafgyt
2025-05-13n/aelf 1115f758d81297173822b6403732150d67679c78959e03e4ca859337be0821f0n/aGafgyt
2025-04-22n/aelf 41353d21cfffc533bde57fc62706dbd37635ab543634dd958703c7b9f5d32710n/aGafgyt
2025-04-19n/aelf 71c258280818b8de50a7a2527509c961bd8c5d5ffc083da81c3f67dde454c890n/aGafgyt
2025-03-27n/aelf d49cb41dedd926fb75dd7e41f58549d7f5598801cc80fc1a60d491fae39a02a8n/aGafgyt
2025-03-26n/aelf 2a9e44ab7b4a86d500d67d0a495e4fd1d27c535d26d3a4fa05a88f126e3cfc54n/aGafgyt