URLhaus Database

You are currently viewing the URLhaus database entry for http://mta179.insuretn.com/bins/jklmpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3424106
URL: http://mta179.insuretn.com/bins/jklmpsl
URL Status:Offline
Host: mta179.insuretn.com
Date added:2025-02-02 07:36:20 UTC
Last online:2025-03-10 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-02 07:37:06 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 5 days, 18 hours, 34 minutes Bad (down since 2025-03-10 02:11:14 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-07n/aelf 0ee587fea341d9da43777102b508c6017d29ad537594afa596e042d4ecd67cf8Virustotal results 53.97%Mirai
2025-03-04n/aelf 308829526df3a508194f0f83a7e9d158acff97b7fd0909e59eee07f93592ad28Virustotal results 25.40%Mirai
2025-03-03n/aelf c38fbee1174b15bb24bf49217c76ea9da5bbbfe7ff9dfa50de27dbe9da663bb5Virustotal results 25.40%Mirai
2025-02-25n/aelf 7d5bc55619c9b5000346cd73a3310787069ecde3df26ad2f9e965725ad39f975n/aMirai
2025-02-10n/aelf 3132f0d33ba9fc64e8258e2094745f4fe60d4f044b5b8fe0aef5e311d9e0adafVirustotal results 25.40%Mirai
2025-02-02n/aelf 78252e14eeda8cff3c5ee0e77d917254cbde21cfd942ceb7ac25d6a65241ae6eVirustotal results 47.62%Mirai