URLhaus Database

You are currently viewing the URLhaus database entry for http://185.208.158.140/bins/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3575251
URL: http://185.208.158.140/bins/mpsl
URL Status:Offline
Host: 185.208.158.140
Date added:2025-07-04 04:23:10 UTC
Last online:2025-07-15 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-07-04 04:24:11 UTC to abuse{at}globaldata-cloud[dot]com)
Takedown time:11 days, 13 hours, 0 minutes Bad (down since 2025-07-15 17:24:12 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-12n/aelf f0c4dc9e697cc34437766c67140cc210be04bd62997bf2ace3c389e3d9e32ff7n/aMirai
2025-07-11n/aelf 3ff483caceb7394b63f0479f1d4e88a087ae59f399aebc5814c444a2e079a2b7Virustotal results 45.31%Mirai
2025-07-09n/aelf 4441fc52f63958eec275f793c5ddd1339acb1e4929893f1ceec4150f7ac1c7c8Virustotal results 54.69%Mirai
2025-07-04n/aelf efa21c733026babe9d74a1c2529eb4604e0900031446d10133efc982f131972dVirustotal results 51.56%Mirai