URLhaus Database

You are currently viewing the URLhaus database entry for http://mta179.insuretn.com/bins/nklm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3424043
URL: http://mta179.insuretn.com/bins/nklm68k
URL Status:Offline
Host: mta179.insuretn.com
Date added:2025-02-02 07:36:14 UTC
Last online:2025-03-10 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-02 07:37:05 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 6 days, 5 hours, 12 minutes Bad (down since 2025-03-10 12:49:43 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-10n/aelf c492fcd6331bbf58b115d9b73bca526ffaafdc7940dc4a07bef529bc4e69b451n/aMirai
2025-03-06n/aelf bdadd11f7ebb796007a6c6dde13e0dbf771a681f18aa87533a1da8e10237b13dn/aMirai
2025-03-04n/aelf 8600c3dbe9120e7b0310730a4c95b9c8d46479fe9df8bfa71332edef4db0231an/aMirai
2025-02-25n/aelf 8b53edd65be8be2f505a557b83b1c0e5c95d4f0b8e1a5568fb6494ee00141e17n/aMirai
2025-02-10n/aelf 5288bd0dc99091790baf2a0d254e39ff72532ac7e00cf5718fd91a0dd9bc83b2Virustotal results 44.44%Mirai
2025-02-02n/aelf f15230e5d5320e0e5fc0444a3ef53cd55c267cb8e3fa6c19217c2e639c32717cVirustotal results 54.10%Mirai