URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.spc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3716506
URL: http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.spc
URL Status:flame Online (spreading malware for 1 month, 26 days, 14 hours, 37 minutes)
Host: 158.94.210.88
Date added:2025-11-25 14:05:14 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-11-25 14:06:14 UTC to abuse{at}lanedo[dot]net)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-19db0fa4b8db0333367e9bda3ab68b8042.spcelf 4b0886c739672baa51a2b187f93271e1c15b56450a29a4d39d6b7709152aa645n/aMirai
2025-12-15db0fa4b8db0333367e9bda3ab68b8042.spcelf 7f00666fab659db27b20c478a3f310ba9c423beebcbf0408ecb837cbec70831en/aMirai
2025-12-05db0fa4b8db0333367e9bda3ab68b8042.spcelf 9c08e0232337e3288d21e5f278f98d2a7d514763b85aa5d79c3588e81037ec5dVirustotal results 67.19%Mirai
2025-11-25db0fa4b8db0333367e9bda3ab68b8042.spcelf 44ab9070ccf7753d5e0cd3eba8625f2eed3e4f382bcb5789049efd299d84e633Virustotal results 60.94%Mirai