URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/lmpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623689
URL: http://158.94.209.216/lmpsl
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:16 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:12 UTC to support{at}ipv4[dot]global)
Tags:elf gafgyt link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 4ac97c2ba6895c1eccde62e0a611950774e1c89b7bba8bca6d2355a372b5dc42Virustotal results 15.62%Gafgyt
2025-09-29n/aelf 4d3bf5e167b63ad7d4c2ab123241bbea71faf2e13378f5433ee566d48c828333n/aGafgyt
2025-09-28n/aelf bd6df2456a92dc1f91db7e6cbeee6218d772152151043568117e34199b6ef354n/aGafgyt
2025-09-26n/aelf d3832cfc74326268777be4bf69df4f298e51e6ab6f0753e2dd838723a5ad14c8n/aGafgyt
2025-09-14n/aelf aea8ad044799f08ef2a9d6bf1617de28d4669ba1fea99f308550af3c87b70349n/aGafgyt