URLhaus Database

You are currently viewing the URLhaus database entry for http://mta179.insuretn.com/splppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3424051
URL: http://mta179.insuretn.com/splppc
URL Status:Offline
Host: mta179.insuretn.com
Date added:2025-02-02 07:36:14 UTC
Last online:2025-03-10 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-02 07:37:05 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 6 days, 2 hours, 48 minutes Bad (down since 2025-03-10 10:25:52 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-10n/aelf 2b7b6286c6d5816897387cc38e7dc0f0c10043461a70b5f97780997e8616fd0fVirustotal results 26.98%Mirai
2025-03-07n/aelf 33d02e315513740f90f8c073885972b54d7a83209b6f5602db5e68e2e28607b8Virustotal results 49.21%Mirai
2025-03-04n/aelf aa5c06244308642a9720339ea69617fbe284808e99dd4f3ca8dfdfa94ebb269cVirustotal results 26.98%Mirai
2025-03-03n/aelf 10eede14018ce25014f005fc7dce2d7403ad43a0c7ddb19ca8f8c3eefc9e0e0dVirustotal results 27.87%Mirai
2025-02-25n/aelf 3a0b786a0e94a3106183386d83a0053c8263b271731530f4da0c83036abc58f2Virustotal results 25.81%Mirai
2025-02-10n/aelf 55c734881414c8ccb0beb999c669cca04a5df36c487846f4694e843a35a96530Virustotal results 27.42%Mirai
2025-02-02n/aelf 1978bfa8e91b6aa591b6d4aab2f42959d9bafdd3ee3a9a54127ecb5f23ec377dVirustotal results 42.86%Mirai