URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/umpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623688
URL: http://158.94.209.216/umpsl
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:16 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:12 UTC to support{at}ipv4[dot]global)
Tags:elf gafgyt link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-01n/aelf 12c372364b5aa742ea607ed72288b85614f9bfe17f0fe683e882a53841ac67e6Virustotal results 15.62%Gafgyt
2025-09-29n/aelf 81015f93996a249d7b3c22acf5690c887fd6f81b35b8fcf38eaec9800fbef9c9n/aGafgyt
2025-09-28n/aelf 96eb398a16dbda6cdaf6f504361918f2bf3f1ebc0c2d3dec6e0f64af0c47d649n/aGafgyt
2025-09-27n/aelf d68479a0c09fc0b96c040d7f5f789c0cf957a62762555c757dff132028ce1a93n/aGafgyt
2025-09-25n/aelf 1331eeb3733ea2b5de0e5c3f20bcd7de7de972a40b70856175958fa6e0a9490dn/aGafgyt
2025-09-14n/aelf 3f94217a2beb9da73f517e722a5e071fe21e24306d246183f469d536ee4f7c12Virustotal results 24.19%Gafgyt