URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/lmips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623686
URL: http://158.94.209.216/lmips
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:16 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:12 UTC to support{at}ipv4[dot]global)
Tags:elf gafgyt link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 0745fcda8a233c6f454cb78462c28dfa64bb5dc4b349c764a74bb3c01dc8a354Virustotal results 21.88%Gafgyt
2025-09-29n/aelf be1d49ac19cca4e0a8a784463dc1f9cfb29c032914637652b71f931637e10bd5n/aGafgyt
2025-09-28n/aelf 34aa88705b24066113d5ba0f35ceeed349305c575af82ae9711bcd93ccfb32e2n/aGafgyt
2025-09-26n/aelf 11a19bc7f2a4b2c5e33f603d563716da355074a85a4846ac01a96366e68ef654n/aGafgyt
2025-09-14n/aelf 8e8239ebc8b41e0cb7f7452f6293f5a5dd4d2f7bd706df0f9e399413e8df328bn/aGafgyt