URLhaus Database

You are currently viewing the URLhaus database entry for http://193.143.1.32/splmpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3422952
URL: http://193.143.1.32/splmpsl
URL Status:Offline
Host: 193.143.1.32
Date added:2025-02-01 13:38:16 UTC
Last online:2025-03-10 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-02-01 13:39:07 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 6 days, 14 hours, 26 minutes Bad (down since 2025-03-10 04:06:06 UTC)
Tags:elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-10n/aelf f135cf3046be829d6f1b7ef020c5dd9eca385aed561d782f8b4d03220a2a833dVirustotal results 25.40%Mirai
2025-03-06n/aelf fa19a01b6bfd5bd2bbccabb27ea70f1554686075982f9e9e4ed307bbe3785c77Virustotal results 25.40%Mirai
2025-03-04n/aelf ac50ba415d197547b2f22913d4d2988ca2dc29d52704175504119efb992f010bVirustotal results 26.23%Mirai
2025-03-03n/aelf 4d444a20cc60e4911f2a402ab8924b2feec6eec72b9022da70e2e06799254194Virustotal results 27.42%Mirai
2025-02-25n/aelf 4ff0e1c0de00271a7cc9e0c1dd5167ae0f1c2903c67a2fb2b51eabc87e407559Virustotal results 25.81%Mirai
2025-02-14n/aelf 18c99e6db38118a4d50a0bca8dd475f700d3ff172a73fb6a48bdd599d4abae95Virustotal results 58.73%Gafgyt
2025-02-10n/aelf 7d5f6cd8bd60edcefe3bf2cc6471d715193ba14dff7fcfcd4f0a5447a9525d91Virustotal results 25.40%Mirai
2025-02-01n/aelf 373bfd3607320c5a7019353e020b6f6f00e035671ef75d76473ca5c92577e102n/aMirai