URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/b which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3579321
URL: http://158.51.126.131/b
URL Status:Offline
Host: 158.51.126.131
Date added:2025-07-09 04:58:16 UTC
Last online:2025-09-07 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-07-09 04:59:12 UTC to abuse{at}hostodo[dot]com)
Takedown time:1 month, 29 days, 21 hours, 42 minutes Bad (down since 2025-09-07 02:42:06 UTC)
Tags:gafgyt link mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-30bsh 6039b90a4c53fbdcdc69be41e0041e737f317ee1e017eff68c9b1bddb83bdaa8n/aGafgyt
2025-08-23bsh 7a7b856c118fa42d7e199384f978635428af34556e2fdec10e8383ad656de527n/aGafgyt
2025-08-16bsh 297828a8202890652a753949da91a689d9de73bc8364e4e3da1f4f97ef139b3bn/aMirai
2025-07-13bsh 36c6120f4329bdf19472571a264344cfe6911b23a59f0896de3f61e96219d264n/aGafgyt
2025-07-09bsh 818f65dbf513517cf5344a5c48f6bb72bc245857246375977db610d0e7e955d2n/aGafgyt