URLhaus Database

You are currently viewing the URLhaus database entry for http://www.secure-network-rebirthltd.ru/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3379708
URL: http://www.secure-network-rebirthltd.ru/mips
URL Status:Offline
Host: www.secure-network-rebirthltd.ru
Date added:2024-12-28 20:09:07 UTC
Last online:2025-02-11 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-02-10 19:12:05 UTC to abuse{at}btcloud[dot]ro)
Takedown time:1 month, 14 days, 9 hours, 39 minutes Bad (down since 2025-02-11 05:50:17 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-10n/aelf 0c4618c5f0a988c3f0205aab766a9b48d71d649e3c1a49042b1df90b949a5a5bn/aMirai
2025-02-01n/aelf 83f5446aa8a1af0ec1e8a2f82e2afbf81df31c9cf801cd591e2fea0f1c44ec42n/aMirai
2025-01-03n/aelf 834cc6baf7ebac043e45709e9b8f0f1392ec77636c35e4db9aa4c689e31e1c07n/aMirai
2025-01-03n/aelf 762c97ff81ec7771c367fe72db4d9b2b36bdfb98af57fa9a1212e42f27a28791n/aMirai
2025-01-03n/aelf da3380381bd33208df103715f50f5c39f6c18b278a3d38600fe42bf0b2fe8dcan/aMirai
2024-12-28n/aelf 1a277c37236c7f81798518774b8a503060f075c2f5f80d8891737f099568b0cdVirustotal results 20.63%Mirai
2024-12-28n/aelf 23918c7b1189ecd5893e8e16739f30745f33382c14979dbbf8136541d401ada4Virustotal results 28.57%Mirai