URLhaus Database

You are currently viewing the URLhaus database entry for http://185.244.36.200/mpsl?ddos which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2890622
URL: http://185.244.36.200/mpsl?ddos
URL Status:Offline
Host: 185.244.36.200
Date added:2024-06-15 14:40:07 UTC
Last online:2024-06-23 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2024-06-15 14:41:07 UTC to abuse{at}spectraip[dot]nl)
Takedown time:8 days, 6 hours, 30 minutes Bad (down since 2024-06-23 21:11:35 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-06-23n/aelf f084e89531c13f76bd44fe76c8f8af88ee3fb75b1258bf81c84629f125d45f61n/a 
2024-06-23n/aelf c6b09545007d8ffc07da8e8aef3ea20dc7860476bcf3b2ac8f2602faad0f731cn/a 
2024-06-18n/aelf e53e1b594aa83596cfc7da361bd42a284861183704bd9360841de59f59952294n/a 
2024-06-15n/aelf 6fdf5b4b08a5894339c26249e190ce627b9585af846573098bed2c050d0ae80bVirustotal results 54.55%Mirai