URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.210.68/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3760588
URL: http://158.94.210.68/mips
URL Status:flame Online (spreading malware for 21 days, 23 hours, 45 minutes)
Host: 158.94.210.68
Date added:2026-01-20 10:34:23 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-01-20 10:35:17 UTC to info{at}apiversa[dot]net)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-23n/aelf 1fb32d9130b8d5c7919259e77f454ec6fecc2d3569a569672460c71ec166412en/aMirai
2026-01-23n/aelf 6d4331007553a1ecf7b544702a411af38355ee36d119f5715d799d4eb9e19d01n/aMirai
2026-01-22n/aelf 2991389b73f7ecd13232aa10a5e48e1df2a67e142db2bb6cc58b17b73f0c6d7cn/a
2026-01-21n/aelf 9f426ecd568eb7956ce9db397467e8cf5e4915200957f69ee29334ac77f48c48n/aGafgyt
2026-01-21n/aelf 398897f7c84071459c645495bc5957eb0df96f843c4b0f5fc981cf9abafa41f7n/aMirai
2026-01-20n/aelf bccb00ec8c6ef15337c9ac6298cc9e7ba684591aee7c346ca5d3046a22d64cf0n/aMirai