🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://104.168.4.206/dissmpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3927809
URL: http://104.168.4.206/dissmpsl
URL Status:flame Online (spreading malware for 2 days, 10 hours, 48 minutes)
Host: 104.168.4.206
Date added:2026-10-03 16:50:22 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-10-03 16:51:19 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Tags:censys elf gafgyt link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-10-05n/aelf dc2450e8cdaf1de56a2ff4ee68fcda754c244a2c90cf4e6cc08fdf9b480b6352n/aGafgyt
2026-10-05n/aelf 46db514c0791f4093050cad13f69dd6cf207887992104b57ba3bca38d38ba14cn/aGafgyt
2026-10-04n/aelf 7edc9df1fd33d9b00ba4013307b3574ea2b772e8b055029b0c5309c59c935025n/aGafgyt
2026-10-04n/aelf 3af5d15c8bc300ef4cce30f60613b5a47cea92c4b23dd0fe0f2ead2b781e9cc6n/aGafgyt
2026-10-03n/aelf 3ce5f9e3c75180effdab51f29f1a6c7833362e2e515f9bdc6b9cfe9347c80bacn/aGafgyt