URLhaus Database

You are currently viewing the URLhaus database entry for http://160.250.134.51/skid.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3620087
URL: http://160.250.134.51/skid.mips
URL Status:Offline
Host: 160.250.134.51
Date added:2025-09-08 15:53:10 UTC
Last online:2025-10-04 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-08 15:54:09 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:25 days, 10 hours, 56 minutes Bad (down since 2025-10-04 02:51:06 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-21skid.mipself 7cd5fb5b6d94ac2acf16f8904f6f307f47710df1d51129d55e70590a52dcf823n/aMirai
2025-09-21skid.mipself 6f461ed0b332339c2e9808b5938ada8ae13f6ee27ed4722f91a100f6acbdde6cn/aGafgyt
2025-09-18skid.mipself fa96cf95515c5e6f86084aa51099fb5e5c0cec71c651bf08ec7b53b2a3029705n/aMirai
2025-09-14skid.mipself 656fbf26390a239a6f852ac5a5e9e11ac7bb245fed072d11e8f1e66ea66d7815Virustotal results 20.63%Gafgyt
2025-09-12skid.mipself 3c49de25e5bf45572154d076f86e35b2ecba09f057641d6953302c8c706bf8f3Virustotal results 34.38%Mirai
2025-09-09skid.mipself 08fc70dcc2fee6611b7f92c7153d39a7ae8cdc672151af202e92cc913443901fVirustotal results 20.63%Mirai
2025-09-08skid.mipself b4854e6a3a95d83dd16aee1c9695602a1978c0aaf8911d3d439d9b39bf00cc2dVirustotal results 45.16%Gafgyt