URLhaus Database

You are currently viewing the URLhaus database entry for http://154.205.128.91/zd/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3469850
URL: http://154.205.128.91/zd/mpsl
URL Status:Offline
Host: 154.205.128.91
Date added:2025-03-06 21:28:04 UTC
Last online:2025-04-16 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-06 21:29:04 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 10 days, 17 hours, 3 minutes Bad (down since 2025-04-16 14:32:33 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14n/aelf e7456b1d11d5e7fe732d7d50cdf1e365f85e6538a2dc3fc444e8ff7b665faf2an/aMirai
2025-04-12n/aelf 94b38528bac1450bf03b092169fb39ef76e88669dfc0d0e17ec90226fe31b91dn/aMirai
2025-04-02n/aelf 9715f270e8d5bd2cf1b846042a9857c22f8d53ce3fe1489f57d2b7a0b491b3c8n/aMirai
2025-03-25n/aelf 306e1f4d881fdfc78b657f08e511933cec1d9708bf75be486d49c1566d0c8465n/aMirai
2025-03-24n/aelf 14bcfb691be61989fc0eebecd012f4041000d2dccffe2201b39c7380e8d4534dn/aMirai
2025-03-17n/aelf 7baaab7e37ae3bc4c662bd7a5f690874f079a26e95b9042b6a4ebf5af320ccffVirustotal results 29.69%Mirai
2025-03-14n/aelf 829d8185ab6e7f4c9d6f7b8634995e4776f347390825f89faac5bbb1e2482113n/aMirai
2025-03-11n/aelf 727ab7f93b95e81c87b0d0d06786417b499385223002cdeaa21c1e7e8a4c8c94Virustotal results 6.25%Mirai
2025-03-09n/aelf ef327b4a363c4113b9f2eb88c3e82a85d28a40197e63226690dd53d1be98ce82n/aMirai
2025-03-08n/aelf 8d95baac849f66967439426428fb2c0578a4f4582d92c2ff979425dff376aa29Virustotal results 7.94%Mirai
2025-03-06n/aelf 0fd36f80ac3ecfac531055721db08212d5c47565ca327b8fc4ede7b9dd84cb78n/aMirai