URLhaus Database

You are currently viewing the URLhaus database entry for http://sex.secure-cyber-security-rebirthltd.su/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2803845
URL: http://sex.secure-cyber-security-rebirthltd.su/mpsl
URL Status:Offline
Host: sex.secure-cyber-security-rebirthltd.su
Date added:2024-04-07 15:44:03 UTC
Last online:2024-05-01 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-04-30 00:41:06 UTC to abuse{at}4media[dot]bg)
Takedown time:23 days, 21 hours, 17 minutes Bad (down since 2024-05-01 14:25:56 UTC)
Tags:botnetdomain elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-30n/aelf 4b60839a2a927b194446e8f9a3148fc4fb85193883bdc4e129cbc15e6b74fc2cVirustotal results 42.19% 
2024-04-15n/aelf 1c4cc8c5b60aba4ad5467569c96617eebac936e3c684361c049c22557197791dn/a 
2024-04-15n/aelf f184e0e6b06e1f55b9ccb5d677ff8cc08305ba626eb738f23d78d800eaa9c87dn/a 
2024-04-15n/aelf d45469982aa1fadc05736da14da3711b8d3b44eab2528fa9792d7dd340f48c1cn/a 
2024-04-15n/aelf 39889930241dcbe7163e948eb449b7b20f7d66d9938f15af60a89605de62f64fn/a 
2024-04-15n/aelf 398cda6b6b34b60121b8135a8fe47b9296ce69244f00dd7a31d1d5deade00143Virustotal results 35.00% 
2024-04-14n/aelf 88f2da599d79ebf48b03b1ddc26768ecfb44b8e7572f7784bd93034790a6e5e9n/a 
2024-04-14n/aelf 62e7c6120e773ae30ce961789c8d48af575053e403a6cfecd4f739cbd6019b83n/a 
2024-04-14n/aelf 2c1bc8d8a760fea6b05d9d139efce9bd1ef1992bffbc805527f45888d4add17en/aGafgyt
2024-04-14n/aelf bc4da42c12b2a86cd2421379f331f2ae014077dcfbbe08c6dcfafd6ecc4af9f4n/a 
2024-04-14n/aelf 346586a7bdb51c4b2ef7849b1225a29a9e34dfce3eddd21a97648f2c153b4c2dVirustotal results 58.06%Gafgyt
2024-04-13n/aelf 1f5a2002fc434f0f2323a882a94856cc85b1788bc7094071089d357c2e6a7d66n/a 
2024-04-13n/aelf b2636a0a8e236405bd3d9e233b657869ea12632716adc58dead34a758b17d6d8Virustotal results 35.48% 
2024-04-13n/aelf 7a3d57c70755a74989ce4e872a08be040ff099a183a2f5d5250f4f472502bdeen/a 
2024-04-13n/aelf 5ce59175e122f6bbd7ac6e29ad1827c11541c6327d779a22374f5de59759d4bcn/a 
2024-04-13n/aelf 34bbcfe13a6a7aac2e58d25bf007b36b5299f6fa2384554a133899606f2e9d02n/a 
2024-04-13n/aelf eb218fce06ead984abf68a3a3dbd748f140253543421b71846f2edbd12f710c4n/a 
2024-04-12n/aelf e70bd8118db93cd10be5662bbd9c7e98b983241c42439d8f80c7df5855672acen/a 
2024-04-12n/aelf 14d8d38a3368eeeca5796d6d2363751be12e83fe6c34b0f1d8e1cb85c86dc85bn/a 
2024-04-11n/aelf e6505bc59ea5d45fd3d03a64705fdf485d3d89f8b6de5bbae9a0445018115f10n/a 
2024-04-11n/aelf fcbf0de39ce36a0035dbb7eeece5577afcefb1dff55999c03039b1c68c092c3an/a 
2024-04-11n/aelf 0d89c40bfea4ca9fae1cdd357f8d972c4a3e7e93606a52a4f8fb55f08e513ea3n/a 
2024-04-10n/aelf d4fc64640758ff9fb5b3a11ae81d564dbf7c96cd036b9dfcb57cf3728ee5c1ccn/a 
2024-04-10n/aelf 4609331d3809e9df15f874400be7bcc2513ccdd361bc95382525c63827101c8bn/a 
2024-04-10n/aelf fe3ab0a8a9a29fe6b06ca3d8755504bde2297f9e7517b0d922b68bdb21bd9df4n/a 
2024-04-10n/aelf aaf4f5499d3ff70cf2f51e4573c4473236dd1ca694596bce6a58b6c9458c1f0aVirustotal results 34.92% 
2024-04-09n/aelf 3f4f1ee0928b013e28a29838907de1962161236d8d7024d63970283e23cbd2f6Virustotal results 31.75%Mirai
2024-04-07n/aelf ac5acdb8a4328e3d82ab2cbb7610a919d5640c692f631b08aae044bd5da6a13bVirustotal results 33.33%Mirai
2024-04-07n/aelf dbdfb7f3f7193883d3baa0b4dc04350d6ef3bd08a2707da4c36be908bfe18673n/a 
2024-04-07n/aelf 25330fc885cdd0652390074c9277b5a1d86a7145ac6cba85465f9bba9513ef61Virustotal results 33.87%Mirai
2024-04-07n/aelf a5f6d21d5e63d360cd4fa1dad60f85e2a417896fef9ef2414d8c64dce1086691n/a