URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623694
URL: http://158.94.209.216/x86
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 17 minutes)
Host: 158.94.209.216
Date added:2025-09-14 11:34:16 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-14 11:35:13 UTC to support{at}ipv4[dot]global)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-03n/aelf 718b6ccd37eb6299854488a68018e6d4d514971b7cdd8de4eb2c0d4eaafc3006Virustotal results 20.31%Mirai
2025-09-29n/aelf 73ac97f2c91f233c476208f62e771ef3d41655660f98e4cd5d07ad28f571ba44n/aMirai
2025-09-28n/aelf 5dc6ee2608b0415093795c46785258357b73f9dd15bd0e992283560a853a0b5bn/aMirai
2025-09-26n/aelf 5cfe5c26a62b475a28b87bceef91e581e9b656671dc7d4e35a61f43708ec8007n/aMirai
2025-09-25n/aelf 3a4861106d76226099d4725979b7d95010900120e85f1034edc1a28b5e669680n/aMirai
2025-09-14n/aelf 319be0c57536a1e1f191f508a1acf397993c6967d2da9f897e318fa0b3758f77Virustotal results 55.38%Mirai