URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/umips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623679
URL: http://158.94.209.216/umips
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:12 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:12 UTC to support{at}ipv4[dot]global)
Tags:elf gafgyt link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-01n/aelf 204694442ce29b4de5a53ac66e3ee7e4bde91ea779981f8ab86b97a23078bfdcVirustotal results 31.03%Gafgyt
2025-09-29n/aelf afc70a5a7efc127587ca7c0bc7b12f05ebcab374ac94e703c61be2d982c46b63n/aGafgyt
2025-09-28n/aelf 313ac9ec857f5ea5923b6ebd49e30ac238d81b7ed3d57a367fd410c6d164e725n/aGafgyt
2025-09-27n/aelf 8404cf657f2d760e070122795bfceee6d09ee6107875083e253973449cd36b2cn/aGafgyt
2025-09-25n/aelf 7b5617e75616fc00373914bdde4e73d5e60279a646d185078c73ba26f7debcafn/aGafgyt
2025-09-14n/aelf 8649694a0ed35070ac5750375437f8da530c58a894beb886d9cffb5f5a4bb088n/aGafgyt