URLhaus Database

You are currently viewing the URLhaus database entry for http://45.125.66.90/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3305152
URL: http://45.125.66.90/mpsl
URL Status:flame Online (spreading malware for 1 year, 0 month, 18 days, 8 hours, 38 minutes)
Host: 45.125.66.90
Date added:2024-11-26 12:33:06 UTC
Threat:Malware download Malware download
Reporter: Gandylyan1
Abuse complaint sent (?): Yes (2024-11-26 12:34:10 UTC to admin{at}serveroffer[dot]lt)
Tags:ddos elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-07n/aelf 449e30caaa96c2833e4f381071095addc874ad4bab41e21225acf6356145c0edVirustotal results 53.12%Mirai
2025-08-19n/aelf 7b9f4b7edf7cc63b2449f64aa14d008b310b0ee1bd3f5b42e1f0445bbee3e507Virustotal results 10.94%Mirai
2025-08-18n/aelf 2a28b7e37fed807e966762b43e82f86685ad180a0ffbc71ea1dfce16b4809351n/a
2025-08-18n/aelf d8a64d074f90c500a8e5d4b0f46b77461b8b9664a52a012711bf5d10c4f34935n/a
2025-08-15n/aelf 4be9abb753a06818c4fcf20985cd3723bd59294e02705bd660df438e52f805c6Virustotal results 29.69%Mirai
2024-11-27n/aelf fdffe57e6c175965878f5632b1ae9e5d44bceda2c2f586d15b204fffb631e84an/aMirai
2024-11-26n/aelf b1e8713db49c15b272baa11e5569ecb4f22fd6064f5aa59ed236d0af58f159a1Virustotal results 51.56%Mirai