URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/n/mipsel which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569506
URL: http://158.51.126.131/n/mipsel
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-23 10:32:06 UTC
Last online:2025-09-07 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-23 10:33:11 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 15 days, 15 hours, 38 minutes Bad (down since 2025-09-07 02:11:33 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-01n/aelf c14f3c5adc33a437a16c0ad651eb6b0e493c6fbcb2ff5d9fd4624666bd4f9034n/aGafgyt
2025-08-31n/aelf 0d43a9a40e9e5dfe76174bb5588031e77b3ba62f87960b7a0f2ac5ce67ec1ccaVirustotal results 42.19%Gafgyt
2025-08-23n/aelf 2c7847c6e3b3246be51a9854113b7af04d888317c1d01bbfaf3fda91ef17f9b1n/aGafgyt
2025-07-14n/aelf cc892279ff8c8e0a545ce4691da5eaea697e3bc4bc4fa9c5b915752cd5e71c4cn/aGafgyt
2025-07-09n/aelf 79d7c5577bfc7a10915966edba0b9ec379f702d5e5ab5ec0c87fef1794a97f09Virustotal results 40.98%Gafgyt
2025-07-09n/aelf 998a713068ab998a6544e4dc420fff342969743b95fd4aafcc52a3339f5590d8n/aGafgyt
2025-06-23n/aelf 70826909faaa0cf1cef0391c1c7d0684755d218c138841e07b6d5e5969d67dbbn/aMirai