URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/nmips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623680
URL: http://158.94.209.216/nmips
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:12 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:12 UTC to support{at}ipv4[dot]global)
Tags:elf gafgyt link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 3bb64160fdc9e8aff3cc5528ef5885248501d6a89e04f9caa819006842c56451Virustotal results 21.88%Gafgyt
2025-09-29n/aelf ae5271d503a352451f5b2f150f93b631f05e17b1e84b8fe4fdb794f53c6f7e26n/aGafgyt
2025-09-28n/aelf 0942508329a8d8d713d886b3f3e40c8bcfb65fcc11adac12366fbd2773a4f98bn/aGafgyt
2025-09-26n/aelf 650ee31d0fc4148e9506c1dd44d19d96b49214f5d69ea3039fe149e0a76b05e1n/aGafgyt
2025-09-25n/aelf fa4f9d3e454aa283652388eebb121d4b168b42a2bf35946953d68df8dfb2bedcn/aGafgyt
2025-09-14n/aelf 38dcb159502b7a01e94d6f45fe145c537dada81778f5e53f734533f03670143dn/aGafgyt