URLhaus Database

You are currently viewing the URLhaus database entry for http://5.181.80.238/lx/apep.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1919768
URL: http://5.181.80.238/lx/apep.mpsl
URL Status:Offline
Host: 5.181.80.238
Date added:2021-12-25 10:35:25 UTC
Last online:2021-12-27 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2021-12-27 10:51:49 UTC to noc{at}4vendeta[dot]com)
Takedown time:2 days, 0 hours, 58 minutes Poor (down since 2021-12-27 11:36:56 UTC)
Tags:DDoS Bot elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-26n/aelf b264c77da1f5fe82ab49ef0485c9e6bad2d92ef2f9fda37ac61d5a6bc6a27f00Virustotal results 28.07% 
2021-12-25n/aelf 3b50dc591336e8c26138f24088a5995226f6df04ec381008cfb2ea75d7e9cdddVirustotal results 44.26%Mirai
2021-12-25n/aelf cb8c84dadf59fa30753ff39f91682babd7197b92f48c7e335876f1d22da6aa05Virustotal results 54.10%