URLhaus Database

You are currently viewing the URLhaus database entry for http://vps.atlas101.us.kg:7768/flutter.mipsel which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3904706
URL: http://vps.atlas101.us.kg:7768/flutter.mipsel
URL Status:flame Online (spreading malware for 2 days, 14 hours, 3 minutes)
Host: vps.atlas101.us.kg
Date added:2026-08-17 05:38:09 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: tp0x
Abuse complaint sent (?): Yes (2026-08-17 05:39:16 UTC to abuse{at}tech-ties[dot]net)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-19n/aelf f2b0de132ef96ef82d4b7d9029f785b69d3255d7cde7a0a4487eb236f450de8fn/aMirai
2026-08-19n/aelf b1f240b7153d4f3e5c6239c00ea341f46e00df99b4e3751d85b341f4a8106b91n/aMirai
2026-08-18n/aelf 5d69309deb323b983cb391a6b37809750d47eb727cfb7e169fbad90ad1572462n/aMirai
2026-08-18n/aelf 3d429645411f7d7abb0e66b239aa8d614ca6b3aa75f1f97df94dbef889c656e9n/aMirai
2026-08-17n/aelf 5a3497b0f01e9204f54e6b853acba1c5e5200393101e623c8f05e86a3446232cn/aMirai