URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.27/bins/pm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740589
URL: http://158.94.208.27/bins/pm68k
URL Status:Offline
Host: 158.94.208.27
Date added:2025-12-22 21:25:15 UTC
Last online:2026-01-10 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-12-22 21:26:15 UTC to abuse{at}lanedo[dot]net)
Takedown time:18 days, 21 hours, 19 minutes Bad (down since 2026-01-10 18:45:49 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-10n/aelf 374b27b29be2d11caa68c2d48e1b9f9935ac0ae37abe50ee5073942cc65f9e23n/aMirai
2026-01-09n/aelf a4a7ee13fd3063fdb06f93ebb0a92b34735b915a67a93c34b1ad2c01396b5841n/aMirai
2026-01-03n/aelf 72bf7021a323e4f8668499f2c124973c6d4744abddab61449824d7b5334249f6n/aMirai
2026-01-03n/aelf fd1902061c9147a53d20b1bb2eea79c15f201380f336036c79554d0f0387f6edn/aMirai
2026-01-01n/aelf d7f6bb3a042143e4d41ec4177016affc949c76c73c4b349ca25fbd367fa662a9n/aMirai
2025-12-22n/aelf 5721490df298019532f4e0826bdfc5e7b73e84a10afdfaf51ee84668746ae1bfn/aMirai