URLhaus Database

You are currently viewing the URLhaus database entry for http://160.191.245.128/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3433731
URL: http://160.191.245.128/mpsl
URL Status:Offline
Host: 160.191.245.128
Date added:2025-02-09 19:37:05 UTC
Last online:2025-03-06 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-02-09 19:38:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:24 days, 19 hours, 18 minutes Bad (down since 2025-03-06 14:56:10 UTC)
Tags:censys elf mirai link moobot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-24n/aelf fb3887f0459af8f20a6368853887281b00e507859955105b0acbb16caa7937f5n/aMirai
2025-02-22n/aelf 7825891cca86b035cfd09bd37f7057851dd52138fe375250fcc40045f9f9c356n/aMirai
2025-02-20n/aelf 07490dde0e5dd1c4c829607096a0fcf1fcc92cd4df0485f5237fa27d385475e1n/aMirai
2025-02-09n/aelf f548b35f052cc1a290e1a2b80dbcd87124e1f120d78f93f2915a99608ceffb6fn/aMirai