URLhaus Database

You are currently viewing the URLhaus database entry for http://94.26.90.217/g which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3531248
URL: http://94.26.90.217/g
URL Status:Offline
Host: 94.26.90.217
Date added:2025-04-30 18:56:33 UTC
Last online:2025-06-29 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-05-01 05:47:07 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 month, 29 days, 4 hours, 52 minutes Bad (down since 2025-06-29 10:40:06 UTC)
Tags:gafgyt link mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-19gsh 38878fae703702ac7413ece24b9b4fc2869c5fc5345412c949553ef874214773n/aMirai
2025-06-18gsh 87b2716efdac9845e154e06eecd1a0a6d08b33d2b84ff677a10e9959fdda6c24n/aMirai
2025-06-07gsh 87bb89b44d5ffa64532c281784b71e8decf4ff55189d130ccf8fd073aa44bf6cn/aMirai
2025-05-08gsh 0d6f83596e208c15cf580393eb91f245b1fb07a9ee8ec34371ca67d94a878429n/aMirai
2025-05-01gsh 16e8da612672b24972cad5449088d13c0a527f7b7a5c74fe922c3c7c591a83ean/a