URLhaus Database

You are currently viewing the URLhaus database entry for http://92.42.100.131/hmips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3858608
URL: http://92.42.100.131/hmips
URL Status:flame Online (spreading malware for 9 days, 1 hours, 43 minutes)
Host: 92.42.100.131
Date added:2026-06-04 10:49:23 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-06-04 10:50:16 UTC to alexcimadamore{at}gmail[dot]com)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-12n/aelf 7b4e23fac930e2c4c3ec03c15adee5a1ed7bf69022c28916f6738f2bc76afe26n/aMirai
2026-06-11n/aelf fa721394c370ee938bb944e37583c7a6b7757dfc0341c76c357011135485d082n/aMirai
2026-06-10n/aelf 2d55364434d8fc2252d45c6e388e457da06519fc711171c6d8ef45aae62a03a5n/aMirai
2026-06-04n/aelf d4437715c226b314218b891c243b2792245fec8ffdb7248223673fc0c1082186n/aMirai