URLhaus Database

You are currently viewing the URLhaus database entry for http://78.153.140.124/b1n/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3687240
URL: http://78.153.140.124/b1n/mips
URL Status:Offline
Host: 78.153.140.124
Date added:2025-10-25 15:05:07 UTC
Last online:2025-11-11 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-25 17:06:11 UTC to abuse{at}hostglobal[dot]plus)
Takedown time:16 days, 14 hours, 47 minutes Bad (down since 2025-11-11 07:53:50 UTC)
Tags:elf gafgyt link geofenced mips ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-02n/aelf e143e72541d710a377db83b1a71968648e8ed280ab9a5ac02cd2678963001fefn/a
2025-10-30n/aelf fc9ee4e4623c198d9ff35eb8563a1efdc3879a0ed40b4c4a4b983c2db33fa46cn/aGafgyt
2025-10-29n/aelf 0f9c2c12f912d2a034bbab31b3ffb6d83fa73b4c434f6e265295cd4f98fbd5ean/aGafgyt
2025-10-29n/aelf e08513676221234b3a8f1b344baca4cce152ebcb7e3d4663a23ea477c8e7c378n/aGafgyt
2025-10-28n/aelf 59d05d35df3c19e3c7faa9a0c3c3b9fef663ec5267a633edf8cead27dfd00f30n/aGafgyt
2025-10-28n/aelf b1f9efeaf5d48b4e3467c69c0987dd0475608c3129cc1f16db7e1fd662ee74d0n/aGafgyt
2025-10-25n/aelf 5613cf6bcbbde41b81f89de026b6fe83864bf71aca0dbb0077bff6c4bc6bc4c3n/aGafgyt