URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.210.88/thinkphp which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3725845
URL: http://158.94.210.88/thinkphp
URL Status:flame Online (spreading malware for 1 month, 16 days, 23 hours, 30 minutes)
Host: 158.94.210.88
Date added:2025-12-05 06:52:14 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-05 06:53:13 UTC to abuse{at}lanedo[dot]net)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-19thinkphpsh d1bd69626e207679d3b239d6925dafebc466a587a564ebafc3de70a3c8ec6582n/aMirai
2025-12-19thinkphpsh 832bf2f75a1ab6d80387c37ca11f2a9c0c3cd217add30c6e7dcc8175c8e18d7bn/aMirai
2025-12-05thinkphpsh 5085fc14f6d90e164ae172b09421d5942a75f742bea42bbcc7e1a7208a7540adVirustotal results 61.29%Mirai
2025-12-05thinkphpsh d4de915f1cd6100a6f97a96305ef79e7c55ca34d4f61cce51925f3ef08c6bfbaVirustotal results 61.40%Mirai