URLhaus Database

You are currently viewing the URLhaus database entry for http://160.187.146.122/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3494038
URL: http://160.187.146.122/mpsl
URL Status:flame Online (spreading malware for 1 year, 3 month, 28 days, 12 hours, 6 minutes)
Host: 160.187.146.122
Date added:2025-03-28 21:39:06 UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-03-28 21:40:08 UTC to hm-changed{at}vnnic[dot]vn)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-13mpsljson 911708b2be1e4952eaa67bca382511067c2ff288520dfc94995a48653cfe201dn/a 
2025-05-08n/aelf 357ec744a44dc3e96b96e9ed41fec9a5824f265b61b7487543bfd7edceb5264en/aMirai
2025-04-27n/aelf 0a3ec5a55f11e205805de24228936bbd011bcd1dbfb9b07a134bcfa07faa56fdn/aMirai
2025-04-26n/aelf fd7872458bd0d3ccd9442990022c48dfb8fffcbf8d72e9d9d4e21c5de2c15aa8n/aMirai
2025-04-16n/aelf e861569f842e2b1b7e144fe7c35c4943c23efff60352c44f441e897d57a02fe5n/aMirai
2025-04-16n/aelf 7023340bee58502b8778be45f91f2e061fd259dd193262880bb221736455e189n/aMirai
2025-03-28n/aelf c39b7121db3907e2ef397491aab24b4b40abb4052794f4cbfce321ea12ceed94n/aMirai