URLhaus Database

You are currently viewing the URLhaus database entry for http://nnmirai.duckdns.org/mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3541299
URL: http://nnmirai.duckdns.org/mips
URL Status:Offline
Host: nnmirai.duckdns.org
Date added:2025-05-11 16:55:10 UTC
Last online:2025-05-26 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-05-26 05:59:07 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:14 days, 13 hours, 24 minutes Bad (down since 2025-05-26 06:20:49 UTC)
Tags:botnetdomain elf mirai link moobot ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-26n/aelf 5b10d7e89b39d77c854dc2236c3707486123f6d549dfc60df895c8dc9342ac68n/aMirai
2025-05-15n/aelf d7b901af36ac50565d06e3ff49cd33a6adf278a331cb3e3784c9f5c7bf1cab89Virustotal results 37.10%Mirai
2025-05-12n/aelf 925583c4531adab4a36032f3df9beaf389d222e5c0497f1f3bdf56889bd4381en/aMirai
2025-05-11n/aelf 46229e24b48ba7c1f238b66acb508be355544a303a93a3348adc8b80d819af59Virustotal results 36.51%Mirai