URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/nmips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3562865
URL: http://158.51.126.131/nmips
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-17 05:25:08 UTC
Last online:2025-09-07 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: vanilla
Abuse complaint sent (?): Yes (2025-06-17 05:26:12 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 21 days, 21 hours, 54 minutes Bad (down since 2025-09-07 03:20:13 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-02n/aelf 15c9ec390182a640ee6e36c5ae36f633ea3c76e82a9a0e7b138283c414d15e27n/aGafgyt
2025-08-31n/aelf 96b058a043817aaba507f170f8ab2911660533583fa99bccd723ef24fa78bea8Virustotal results 43.75%Gafgyt
2025-08-23n/aelf 288f74e1485e02dd9d8a2465870c7a2cd0cdfd7cd37cf0f6dc603321ff2c8025n/aGafgyt
2025-07-14n/aelf 1f88c46bfabb6799f443e31d8591e443c09a5475552231fc95891eec2e4c93d9n/aGafgyt
2025-07-09n/aelf 5087fec6e0a30cdb13126262ef8ae01fafe66068f931246db195368d796fb240Virustotal results 42.86%Gafgyt
2025-07-09n/aelf 937917dc794fc3823723baae1b2ba22ce8ed58a3776c9cceb192315fcd89dcb6n/aGafgyt
2025-07-05n/aelf 5085e00b4976e12b771111d605c7d011309625dd69974e8a4aa2d07017b9ac1cn/aGafgyt
2025-07-05n/aelf 265b0826fa7f5d445b4c1682e49d98bad378ce7035e04facb636132836076d84n/aGafgyt
2025-07-05n/aelf 05c2f3b76e693f82735862e9e6bc44012b61fbcb1c05127b1751f656f7f0fb29n/aGafgyt
2025-06-26n/aelf 0522a90b44c500fb0e8ec1a5eb665005b64ec2161681bc182ae5593cbd06d3c4n/aMirai
2025-06-17n/aelf 85cea6a5e66e9927453054e6045611fb139bf058c797f221831b056bf20a8352Virustotal results 14.06%Mirai