URLhaus Database

You are currently viewing the URLhaus database entry for http://42.112.26.36:8080/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469444
URL: http://42.112.26.36:8080/mpsl
URL Status:Offline
Host: 42.112.26.36
Date added:2025-03-06 13:27:04 UTC
Last online:2025-04-07 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 18:26:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 2 days, 2 hours, 6 minutes Bad (down since 2025-04-07 20:32:46 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-29n/aelf 994cd87c6f0f7edd7efcc88aa5d5ee7b21f2c273cbe8c887363e28f7727a1166n/aGafgyt
2025-03-28n/aelf 5d538a48144268b6f26d3dfd2776ad7ad9cd726e54dfb3dc3a4ec78895a01100n/aGafgyt
2025-03-28n/aelf 9f725587128c1eb840279db0ce8256f9cb8098b742f7f863addf18be610d4979Virustotal results 22.58%Mirai
2025-03-26n/aelf 79f5aa00f16e9497609f034dbc510c2f783b6484ef4fbb7ff2f6e57d16edd0f0Virustotal results 20.31%Mirai
2025-03-25n/aelf cfeed8da9c17c531fe03881f2e08507df2857a42ad1846b650e287e698d70019n/aMirai
2025-03-24n/aelf c459b0b64d37e91c668723d12a97be9e6418f3f8c58179718d649f240019cc8en/aMirai
2025-03-24n/aelf 6d65cc3ac06025cfbde06688b67748215fe4f6be0e4618cb855b77348b4c7e13n/aMirai
2025-03-24n/aelf 1fee23eff67177ad5688147cd88cc78e5642e06245a73954c987cbeb7c5f2caeVirustotal results 18.03%Mirai
2025-03-20n/aelf a15bf9dd4d0aad9778ab4380feb71ca2cf314765a78f8dbb5275f1343a9f5b8en/aMirai
2025-03-18n/aelf a185e9a92684a2e14e390eedae15c8544d435ff6deb8b65e3ad066dd9dd5fa41n/aMirai
2025-03-18n/aelf 681737c2f5febd7e373f54383cbbcd0ba0d1491dff18a0e044517b009a3e98aan/aMirai
2025-03-17n/aelf d6f2e5118e0abba95f9200e5a92cc3e6faf13b4b17235afbfc63abd263ac746fn/aMirai
2025-03-15n/aelf 2e41ced2cc579a618f1d26cb7e63c5116ee0aedb106bc614aca3f416b4c124c1Virustotal results 20.31%Mirai
2025-03-14n/aelf a3e4045d32ba8a3686a20058bde874540560e9e73a9ebd0e42b34fd71ce7e468Virustotal results 15.62%Mirai
2025-03-11n/aelf 9035e13661a599cc829264146be0bc962454d0db765f8d682b01d22da5e12611Virustotal results 16.67%Mirai
2025-03-09n/aelf 629e672f2bfa89b414420a11dbd91c0839ba7b386d84307aa18d6b7d94ef5849Virustotal results 20.63%Mirai
2025-03-09n/aelf 8c41aec4a1020da65bf270df6b681e0cf0da2ef7cd707e3e934997b6546147f5n/aMirai
2025-03-06n/aelf 44e29b1fbfe1a034a6fd7ba0b2f5d9545a49f395ec1b03d71128068357778753Virustotal results 43.40%Mirai