URLhaus Database

You are currently viewing the URLhaus database entry for http://42.112.26.45/skid.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3619880
URL: http://42.112.26.45/skid.mips
URL Status:Offline
Host: 42.112.26.45
Date added:2025-09-08 13:33:19 UTC
Last online:2025-10-13 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-08 13:34:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 5 days, 3 hours, 6 minutes Bad (down since 2025-10-13 16:40:39 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-29skid.mipself 172f9ed2d70b8d7244d57a67d8d9fee3ef1c6b358e8caf7a5d7ec6cf72536422Virustotal results 34.38%Gafgyt
2025-09-22skid.mipself 6dce441b0e72571a06a88a2deff3e7f48202ffcaadae7c59ff5dfe4b71f89499n/aGafgyt
2025-09-21skid.mipself 458d16451d560698eb7b400a071e774fac1ab6b1592f898242f57d29807a7b76n/aGafgyt
2025-09-18skid.mipself fa96cf95515c5e6f86084aa51099fb5e5c0cec71c651bf08ec7b53b2a3029705Virustotal results 31.75%Mirai
2025-09-18skid.mipself fd75057993af111cf29aeb0924554d01ad28c071fb20cf9700831fd4402fbaf2Virustotal results 32.81%Mirai
2025-09-16skid.mipself a7d7c3cba50cf9f5e690acfff4f76cae11f66768271e2b5c78f5b2dcef321a10n/aGafgyt
2025-09-16skid.mipself 11f9e2e61adc0b1539a78e24e90e328ab82160f6a2331c6dd6171b8a810a325bn/aGafgyt
2025-09-13skid.mipself 656fbf26390a239a6f852ac5a5e9e11ac7bb245fed072d11e8f1e66ea66d7815n/aGafgyt
2025-09-13skid.mipself f63008726aad565fd8f959d73b12a05f02900b341cbe0d1596282a7f7bde567eVirustotal results 20.31%Mirai
2025-09-11skid.mipself 8026b23def24266cce96522dd434a6321582d1b6b7eba3aedb79c01ec0b4bb59n/aMirai
2025-09-11skid.mipself ebd502e4fcaf569511911ba06213ff5978f7e2156ce2609b575ace68902daf23n/aMirai
2025-09-10skid.mipself d845e050b81aadb579af479c30a5df58fa87a7a4b6a56758a918579ee0b188c0n/aMirai
2025-09-09skid.mipself 36ea5f45b9d8b2e8c2f682a839369a84d7c28b04e7c0c42ffaf948b4d605cd08n/aMirai
2025-09-09skid.mipself 08fc70dcc2fee6611b7f92c7153d39a7ae8cdc672151af202e92cc913443901fn/aMirai
2025-09-08skid.mipself 32ac889d1867ac1cc4f4040962872c9190ab5f23a92efac460066b0b068d9498Virustotal results 20.31%Mirai
2025-09-08skid.mipself 21c1a38155620df7ff31b34364069137ff5bea0f6cf57a8c8a13a687792a7d86Virustotal results 44.44%Gafgyt