URLhaus Database

You are currently viewing the URLhaus database entry for http://mta179.insuretn.com/nklarm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3423995
URL: http://mta179.insuretn.com/nklarm6
URL Status:Offline
Host: mta179.insuretn.com
Date added:2025-02-02 07:36:09 UTC
Last online:2025-03-10 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-02 07:37:05 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 5 days, 20 hours, 3 minutes Bad (down since 2025-03-10 03:40:51 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-10n/aelf a09ca45bce0085c2d81905a3c745784f791941d7834710fd47fd27f8e44ac7f2n/aMirai
2025-03-06n/aelf 9aba55493e3fbf4fe4686684933709fda97b98be01dc38f4b17b3dbb29bf72e2n/aMirai
2025-03-04n/aelf 9ef9121e0827d542c5523544bfc53cd90189a0763f4fdda84553bc238ef71523Virustotal results 37.10%Mirai
2025-03-03n/aelf b6ad2a298e1960eea57743d06e7a34a7ca608e57e9781fd8800552254633e090Virustotal results 39.68%Mirai
2025-02-28n/aelf 3c7d542e2065d18186bd23bab0c8990ea883a1bdf471f9299d95406341ca0966Virustotal results 61.29%Mirai
2025-02-10n/aelf 988713550709414f8c10d6e7d0913a3a636e684a15d1503d5cbba5683345bbadn/aMirai
2025-02-02n/aelf 6376d40a75feae83ca4b6d293d557c038278d385a33ae1529c33ce667aa3359dVirustotal results 60.32%Mirai