URLhaus Database

You are currently viewing the URLhaus database entry for http://185.208.158.140/powerpc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3572366
URL: http://185.208.158.140/powerpc
URL Status:Offline
Host: 185.208.158.140
Date added:2025-07-01 06:41:06 UTC
Last online:2025-07-15 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-07-01 06:42:12 UTC to abuse{at}globaldata-cloud[dot]com)
Takedown time:14 days, 8 hours, 36 minutes Bad (down since 2025-07-15 15:19:09 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-12n/aelf cefd6e28cd1c138a151a1721dbbe1a53b410424b259179faa792fcc8063952baVirustotal results 58.06%Mirai
2025-07-11n/aelf 544cbcf87d9a592fbbb8f931e3b8e93afb1ff24655e7d6905da7b35d055ee6b9Virustotal results 45.31%Mirai
2025-07-09n/aelf 219906d79878db64864b0df75ca5229007dfc89516265f01aaed5101887da9f8n/aMirai
2025-07-03n/aelf 36d4485e59a43a4bd936bd636007d2dafb5a136b42d6859934db2e147f96dee0n/aMirai
2025-07-01n/aelf ca502d27651e19d7207ad77ee05f70fac09f96c610322f2181112e17f51edee8n/aMirai