URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623625
URL: http://158.94.209.216/mips
URL Status:flame Online (spreading malware for 2 months, 15 days, 20 hours, 50 minutes)
Host: 158.94.209.216
Date added:2025-09-14 09:01:36 UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-09-14 09:02:21 UTC to support{at}ipv4[dot]global)
Tags:32-bit elf gafgyt link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 77637c28bd5ccda2ad3c90c2d34e879fa7e10f1abe04520e5bda11cd7ed69c8eVirustotal results 23.81%Gafgyt
2025-09-29n/aelf e832b1aacc1f802c68e8366c6a79c6eeba30a47e066158f4cd5ccb1ab4eb7b7fn/aGafgyt
2025-09-28n/aelf 2075373a9bfa27126af33153f55608fe5c0d92e2c1cd0601ace742b2a944ac42n/aGafgyt
2025-09-26n/aelf 6ef32b593acfc3e1ebe1dd35a43809aff32a6cbf797295af5b25db2f84e9a5b9n/aGafgyt
2025-09-25n/aelf e3a57555a2bba936cd878c0bcf5df4f7e15cefff60c81870b363c5fa1dd0d601n/aGafgyt
2025-09-14n/aelf c8ab2207a950a19ede5731ba8f655f4465f2e0fc9a9b9364f01a786392a78e18Virustotal results 20.31%Gafgyt