URLhaus Database

You are currently viewing the URLhaus database entry for http://mta179.insuretn.com/jklmips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3424026
URL: http://mta179.insuretn.com/jklmips
URL Status:Offline
Host: mta179.insuretn.com
Date added:2025-02-02 07:36:10 UTC
Last online:2025-03-10 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-02 07:37:05 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 5 days, 20 hours, 27 minutes Bad (down since 2025-03-10 04:04:20 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-10n/aelf 6cb427e528d9d6e68e43e97ff0f81ddd5768458159561d0fafdb5dffd0b6f7b2Virustotal results 25.40%Mirai
2025-03-06n/aelf 6fc1f441c08b49ceb3083fa2a201d424c5282ec7a5cd2431bd017490ba2b23deVirustotal results 23.81%Mirai
2025-03-04n/aelf 1e6cb8599d1e6db4446a9667f7281dc6ca9bc5619b47b7433a956cbdac446a68n/aMirai
2025-03-03n/aelf 1795aa8f2d5c97350a9adff496cf1e4f4d3a50d3e378b1ad92d337451737caf3Virustotal results 28.57%Mirai
2025-02-25n/aelf 5545ceef09efabbeb5fca4e9799c3e692c8347dbef1fa921ec88c077f38c628fn/aMirai
2025-02-10n/aelf 5e2d9f9531aff471dd5d92b772c57ba66cfb39aefef46fb878f3d30db9a8c1c8Virustotal results 27.42%Mirai
2025-02-02n/aelf 834b00373b7c589d9032bc8b06c66adab67ada1e1ae700356f05d252d94c04ebVirustotal results 49.21%Mirai