URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/nmipsel which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3562844
URL: http://158.51.126.131/nmipsel
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-17 05:21:09 UTC
Last online:2025-09-07 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: vanilla
Abuse complaint sent (?): Yes (2025-06-17 05:22:12 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 21 days, 22 hours, 14 minutes Bad (down since 2025-09-07 03:37:05 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-02n/aelf c14f3c5adc33a437a16c0ad651eb6b0e493c6fbcb2ff5d9fd4624666bd4f9034Virustotal results 42.19%Gafgyt
2025-08-31n/aelf 0d43a9a40e9e5dfe76174bb5588031e77b3ba62f87960b7a0f2ac5ce67ec1ccan/aGafgyt
2025-08-23n/aelf 2c7847c6e3b3246be51a9854113b7af04d888317c1d01bbfaf3fda91ef17f9b1n/aGafgyt
2025-07-14n/aelf cc892279ff8c8e0a545ce4691da5eaea697e3bc4bc4fa9c5b915752cd5e71c4cn/aGafgyt
2025-07-09n/aelf 79d7c5577bfc7a10915966edba0b9ec379f702d5e5ab5ec0c87fef1794a97f09n/aGafgyt
2025-07-09n/aelf 998a713068ab998a6544e4dc420fff342969743b95fd4aafcc52a3339f5590d8Virustotal results 43.75%Gafgyt
2025-07-05n/aelf 622ef0d316cff38ad733957a8c8d21ed2bfa01f0ff4ea4e0278f6048c87d8ce9n/aGafgyt
2025-07-05n/aelf b293ed1ec4423106359dd47d8091af20add4e643519e4acd06894ee99d5a6bb0n/aGafgyt
2025-06-26n/aelf c6ef0d4da84a9198072026889c9867a97464f2a8e7cf259d1c391f34d7033e30n/aMirai
2025-06-17n/aelf f9d053169c262407422c8456ebd3d3caf7d91858ebdcd2e870ad65522bffe8e2Virustotal results 17.19%Mirai