URLhaus Database

You are currently viewing the URLhaus database entry for http://mta179.insuretn.com/nabm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3424088
URL: http://mta179.insuretn.com/nabm68k
URL Status:Offline
Host: mta179.insuretn.com
Date added:2025-02-02 07:36:20 UTC
Last online:2025-03-10 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-02 07:37:06 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 5 days, 19 hours, 55 minutes Bad (down since 2025-03-10 03:33:02 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-10n/aelf 98f675b3faa7f68a98229903775d6a1e91d482e648513a331d32c986bc8d57b1Virustotal results 26.98%Mirai
2025-03-06n/aelf 76080498620850aa87e5a0920cb67c28a50aec53b1c5beaf42cb958e8533efa6Virustotal results 24.59%Mirai
2025-03-04n/aelf 46ea8ea614abade8dde327c6f91800071d18421db369602b71ca7c1042026f54n/aMirai
2025-03-03n/aelf a1a75e880d4536441743d652fc51676cbfb32f005484f3bfc1bfcd5023d963cbn/aMirai
2025-02-25n/aelf 6fed3afbf3776d256e808f5ddfb60932733813a47787d961e97017ae1dd5b1deVirustotal results 26.23%Mirai
2025-02-10n/aelf f80431b4dbd1f4c7f773c37259320ab3bdd04248bd9df07057df9601f81ae0e8n/aMirai
2025-02-02n/aelf 6a77fe90837bc31f636e7bc02b31a59968848e07bddd83dfd730e9ef2d61af19Virustotal results 44.44%Mirai