URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.216/ui686 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3624280
URL: http://158.94.209.216/ui686
URL Status:flame Online (spreading malware for 2 months, 15 days, 0 hours, 4 minutes)
Host: 158.94.209.216
Date added:2025-09-15 05:47:08 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-15 05:48:10 UTC to support{at}ipv4[dot]global)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-01n/aelf 51138a0bdded7b065ea2286c581f9b14fe17d904d71aa5cea763b67fb8083b42n/aMirai
2025-09-29n/aelf 438f3aec88817656288ea8feab54ed9e08801010959d533baf296c56151bb413n/aMirai
2025-09-28n/aelf 4368a63b0768b53c10c34e855ab6b91b91a5bc1679d954ac4d5d243b29fe9112n/aMirai
2025-09-27n/aelf 4ca05ef3658f86bea277b9e92a33b4099ac53a5efd5218ef144af75a212776ecn/aMirai
2025-09-25n/aelf f1e2280c33cc3180631a32ce0aa8ee0cc980d39a483616fd106b8b63db83c7c5n/aMirai
2025-09-15n/aelf 16435bb749d835f6acc7a10384554530e60bbd45b978f8d494ab39cfe872a52fn/aMirai