URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569508
URL: http://158.51.126.131/mips
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-23 10:32:06 UTC
Last online:2025-08-23 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-23 10:33:11 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 0 days, 14 hours, 39 minutes Bad (down since 2025-08-23 01:12:50 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-16n/aelf 9045a4035bcbf171d7be31a33fe33496471631a4fe8f6c42a45b4447502d53a4n/a
2025-07-07n/aelf 22ebe0b232b538048d54777e99412db6b5ae75eb8a5650827ba0093461a448e7n/aGafgyt
2025-07-05n/aelf 646d2ae3e741d28448da47078e820f6e08fa0001bc22d82771e922ec0f0230f3n/aGafgyt
2025-07-05n/aelf 5e3c6b1f7838743b43f390c9bcb92da8cb91b0808b0242b45d2ff1af83c5e072n/aGafgyt
2025-07-05n/aelf 9ba1d04bc6bd6a465baa331a188d88781383efc7859070e094666eeb8ea739f5n/aGafgyt
2025-07-04n/aelf b645c7756628438adfea8a850abe014447759e7746a1a5c1bff4014fce4bf97dn/aGafgyt
2025-07-04n/aelf 8fb840ba11b0068e428787994259dd7d6b5dd63b7008710fc6f7ea3491bf13e1n/aMirai
2025-06-26n/aelf 3cbf7e8b7969d1dad586fb5b81ede546876ebcf5cf140e8ac73c71853520ab41n/aMirai
2025-06-23n/aelf 1027488a68cf61ac4fbf798ed1df292635972e80ef132d2534b54142174ae7d2n/aMirai