URLhaus Database

You are currently viewing the URLhaus database entry for http://185.244.36.200/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2880949
URL: http://185.244.36.200/mpsl
URL Status:Offline
Host: 185.244.36.200
Date added:2024-06-09 14:10:12 UTC
Last online:2024-06-23 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: LemonHaze420__
Abuse complaint sent (?): Yes (2024-06-09 14:11:08 UTC to abuse{at}spectraip[dot]nl)
Takedown time:14 days, 6 hours, 58 minutes Bad (down since 2024-06-23 21:09:28 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-06-23n/aelf f084e89531c13f76bd44fe76c8f8af88ee3fb75b1258bf81c84629f125d45f61Virustotal results 43.08% 
2024-06-23n/aelf c6b09545007d8ffc07da8e8aef3ea20dc7860476bcf3b2ac8f2602faad0f731cn/a 
2024-06-18n/aelf e53e1b594aa83596cfc7da361bd42a284861183704bd9360841de59f59952294n/a 
2024-06-10n/aelf 6fdf5b4b08a5894339c26249e190ce627b9585af846573098bed2c050d0ae80bn/aMirai
2024-06-10n/aelf a69c20a0a453f0bda2f41bce5eb68c7bb346b8eb84e990a41e71d930bdbd5025n/a 
2024-06-09n/aelf 5ef135f993370c3f511d821b4b28e78285945562e2fa74afe62a506ac1fd1221n/aMirai