URLhaus Database

You are currently viewing the URLhaus database entry for http://genddos.st/bachekuni/ohshit.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3875525
URL: http://genddos.st/bachekuni/ohshit.mips
URL Status:flame Online (spreading malware for 1 month, 28 days, 21 hours, 38 minutes)
Host: genddos.st
Date added:2026-06-24 12:32:20 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Malware domain
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: burger
Abuse complaint sent (?): Yes (2026-08-18 02:38:14 UTC to abuse{at}stormindustries[dot]llc)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-18ohshit.mipself d2b5a8abdd33271500c062dae49ea54272ea64da77569d413091bf7209bb6bden/aMirai
2026-07-30ohshit.mipself c3eebcc3151c36d88866d401e7e05fd1bd19e18d203bcc485f3decafabb39bd1n/aMirai
2026-07-20ohshit.mipself e7889354c0d2cce6cc0c6a34ec13afd79bf361388e76ed2b3b987e0613d9c6a6n/aMirai
2026-07-19ohshit.mipself 956f66bf9a0d796c9913a9b9cd255e8d1c49ab1b3de29d5418fd01b485032430n/aMirai
2026-07-19ohshit.mipself ee151571aa7e736f1adf36e997afae0590824707fa4c2fb3623c76c1241af135n/aMirai
2026-07-05ohshit.mipself 2a1f933e02eb8ffdc3bac67927935dfc04fb27c2a6b2922d38920b39a8bcea5an/aMirai
2026-06-24ohshit.mipself f9ec1b33dfc61dad616223f2eef5a80d3b9b9165e9035b574eb436b34a78ee8en/aMirai