URLhaus Database

You are currently viewing the URLhaus database entry for http://149.50.96.133/n2/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3711045
URL: http://149.50.96.133/n2/mips
URL Status:flame Online (spreading malware for 3 days, 12 hours, 29 minutes)
Host: 149.50.96.133
Date added:2025-11-18 09:01:13 UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-11-18 09:02:20 UTC to abuse{at}mevspace[dot]com)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-21n/aelf b996086e3bc5fa52f39a8e2d40e36c113f816399305321a0562febb1782066dfn/aMirai
2025-11-20n/aelf 2daf43fb7e635c338f3c37f0109a8cac0d1c15e26c288889512d095f40e556ddVirustotal results 12.50%Mirai
2025-11-19n/aelf c8bdd38673aff456b1ba6ad0a7765d180157a8235ca7113ef04b32dad5cb80ean/aMirai
2025-11-18n/aelf 757693c0a24036d1e19e5b2946ac90ed64bde2a826343cc42ff54bde8d0122e9Virustotal results 50.00%Mirai