URLhaus Database

You are currently viewing the URLhaus database entry for http://185.39.207.89/gmips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3526654
URL: http://185.39.207.89/gmips
URL Status:Offline
Host: 185.39.207.89
Date added:2025-04-26 14:37:13 UTC
Last online:2025-04-29 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-04-26 14:38:06 UTC to abuse{at}globconnex[dot]com)
Takedown time:2 days, 16 hours, 36 minutes Poor (down since 2025-04-29 07:14:38 UTC)
Tags:censys elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-28n/aelf 3387785a975cf1e2e0a65360ea825a5f4f2ea2f544104f44736fd1cab38584cdVirustotal results 23.73%Gafgyt
2025-04-27n/aelf 9c4f95510ba68eb803405b82c2ae227bd62c1736bac3ef4fd952fedbe5b01fccn/aMirai
2025-04-26n/aelf 71b72cd1a57789dccc0d292ec3c4c8559bc4aa0bcc20f41ae7493995e10e9886n/aGafgyt
2025-04-26n/aelf b0179edf1a46c64ea616b8b737a07413750a5c6d5595cd3f86e99d60924fd147n/aGafgyt