URLhaus Database

You are currently viewing the URLhaus database entry for http://94.26.90.217/f which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3531255
URL: http://94.26.90.217/f
URL Status:Offline
Host: 94.26.90.217
Date added:2025-04-30 18:56:33 UTC
Last online:2025-06-29 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-05-01 06:38:07 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 month, 29 days, 4 hours, 11 minutes Bad (down since 2025-06-29 10:49:37 UTC)
Tags:gafgyt link mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-18fsh 96d9954c9085811cfeee16319eaf4458b45a36ac2a07e3a9a18f347e1759a6ffn/aMirai
2025-06-08fsh 64d6e48aa7f2ff487340b01ca679008b738dc3ed03fc01d3cb1b72be59fd0f15n/a 
2025-06-08fsh d54337112ba8fc24e73e532df00204e48fe5eac3bc79c08ddfe19e9950619ed8n/aMirai
2025-06-07fsh 39e82079ff58cb1b6ac6cb38ff9f16786fa04d0df033662432ae53d5a0005aedn/aMirai
2025-05-31fsh c1a81440a53fededc883788eac7c385fabb266b2c6e77c2ef91e70633a358ef7n/a
2025-05-16fsh c2b7280ec40e14a4e3c10c85993cf741c78d1924db750449a7be93a5ca5703a6n/a
2025-05-13fsh b5e92397ee49a35df678e5607386e082befdb7efaa4fdb434778071a6ef548d0Virustotal results 19.67%
2025-05-10fsh 684f2521235470d19da62f352264ea20c89f2261fc9ffc2f9c41291079ec2e9eVirustotal results 19.67%
2025-05-08fsh 873520dd91c6baf2fa08f33477d55957d79309e964edcdad6a0b1806652c0931n/a
2025-05-01fsh 1e0934ec7d8761f32e8b7bc1b3808275004b4256b94c8b75d4283564f5dff465Virustotal results 21.31%