URLhaus Database

You are currently viewing the URLhaus database entry for http://mta179.insuretn.com/splx86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3424104
URL: http://mta179.insuretn.com/splx86
URL Status:Offline
Host: mta179.insuretn.com
Date added:2025-02-02 07:36:20 UTC
Last online:2025-03-10 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-02 07:37:06 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 5 days, 18 hours, 16 minutes Bad (down since 2025-03-10 01:53:49 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-06n/aelf c98e2a6a4e348c46febeea10a60e5f36708fb26d5af1405a97e8ba3e4b1d3257n/aMirai
2025-03-04n/aelf 91cbe54a0e947d0e7f363f7d10002ec215d956382275665ce5273e383bf9dd2bn/aMirai
2025-03-03n/aelf dea8f701059898f451987d3f21d22d0cbc0bc327adecb46fe1aa33544ba31335n/aMirai
2025-02-28n/aelf 4436c5e562b432965918b10188a836b627ca429c0b0b974e1de3f9eaecb80c00Virustotal results 60.94%Mirai
2025-02-10n/aelf 52b394c99019076239382cc462dbf799d3cf9661bf0ad833328c7e54c3f607cbn/aMirai
2025-02-02n/aelf c9e2cf5f4e9f34ec1bb8a14d4aa57d2336cc72b7c0efa86de9bc417a6050ecaeVirustotal results 60.94%Mirai