URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.27/pm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3742446
URL: http://158.94.208.27/pm68k
URL Status:Offline
Host: 158.94.208.27
Date added:2025-12-24 13:36:15 UTC
Last online:2026-01-03 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-24 13:37:18 UTC to abuse{at}lanedo[dot]net)
Takedown time:10 days, 5 hours, 46 minutes Bad (down since 2026-01-03 19:23:41 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-03n/aelf 72bf7021a323e4f8668499f2c124973c6d4744abddab61449824d7b5334249f6n/aMirai
2026-01-01n/aelf d7f6bb3a042143e4d41ec4177016affc949c76c73c4b349ca25fbd367fa662a9n/aMirai
2025-12-24n/aelf 5721490df298019532f4e0826bdfc5e7b73e84a10afdfaf51ee84668746ae1bfn/aMirai