URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.210.68/mipsel which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3760589
URL: http://158.94.210.68/mipsel
URL Status:flame Online (spreading malware for 21 days, 12 hours, 32 minutes)
Host: 158.94.210.68
Date added:2026-01-20 10:34:23 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-01-20 10:35:17 UTC to info{at}apiversa[dot]net)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-23n/aelf 567fa40676b9708ff104a36d4c03af79fcd359b1ae24bcf2a92530e9ef13d849n/aMirai
2026-01-23n/aelf 15da48c82e7b95da9e8c23c1ff0c90e70578da4a521a768dec60528d29235b37n/aMirai
2026-01-22n/aelf 61bb1e7933bda2e8598985731dda6b8e550a810a192b23a10176f2727a6908cfn/aGafgyt
2026-01-21n/aelf 35d754c1126d28bf2ece6a68db5fb683abf5fbe7632eaf3ae38c600d8f5db1e4n/aGafgyt
2026-01-21n/aelf bd968f1043cb459e875d3ea8480cd42f8871300fae0caa67920158bff0d427b8n/aMirai
2026-01-20n/aelf f503f7100473a82b1a5648ccd824d0da7533391445c6f279a8d06d9757c0e9e7n/aMirai
2026-01-20n/aelf 3c3edc152f92bb03bde04d138d6ba83c75744e957b005d52810f7bf9b322b895n/aMirai