🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://94.154.43.158/killbotx.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3896661
URL: http://94.154.43.158/killbotx.mips
URL Status:Offline
Host: 94.154.43.158
Date added:2026-08-04 06:35:10 UTC
Last online:2026-08-07 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-08-04 06:36:20 UTC to abuse{at}pitline[dot]net,abusep{at}kharkiv[dot]com)
Takedown time:3 days, 13 hours, 1 minutes Bad (down since 2026-08-07 19:38:16 UTC)
Tags:censys DEU elf geofenced mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-06killbotx.mipself 024ee12e5b892c7bbb2baa1376f8b85c7c382e0c513071d0ed54b1187da73584n/aMirai
2026-08-05killbotx.mipself bc49f72d368c8d61fe874ec469f18047567327c97cdd737e3d040735eed59ba9n/aMirai
2026-08-04killbotx.mipself 769182c8505feeb18a5810e9fb5709727704739cd6b02068da8352f66ea1c3b3n/aMirai
2026-08-04killbotx.mipself d3a1a95843ae2337510130fa2bb3273866a4b585216851bd27e8472d737bec54n/aMirai
2026-08-04killbotx.mipself 74d09e53de6a151f6240d9d08e74e75baa2c71de5fc6d6c8d6880cc7976cc866n/aMirai