URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.159/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3598089
URL: http://213.209.150.159/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mpsl
URL Status:Offline
Host: 213.209.150.159
Date added:2025-08-07 07:32:06 UTC
Last online:2025-09-15 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-07 07:33:12 UTC to abuse{at}virtualine[dot]org)
Takedown time:1 month, 9 days, 8 hours, 16 minutes Bad (down since 2025-09-15 15:49:17 UTC)
Tags:elf geofenced mips mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-30db0fa4b8db0333367e9bda3ab68b8042.mpslhtml 00be7f643a12ac2221c9ba8df4fb34b3701c336fa830d24fe906c55364ef7b35Virustotal results 22.58%
2025-08-24db0fa4b8db0333367e9bda3ab68b8042.mpslelf 6294a0eb4ee65e6ba006a024522658107ec8753f6d3df2dc7309776199da65e7n/aMirai
2025-08-21db0fa4b8db0333367e9bda3ab68b8042.mpslelf 4ef7d08eb5036da436d6171ed940328835978a74aa3db1b02cea553002114216n/aMirai
2025-08-20db0fa4b8db0333367e9bda3ab68b8042.mpslhtml e480c5556efd90bf1c71eb9a645ad1c7c31b2610f68aec7ac57a28218446484cVirustotal results 21.67%
2025-08-07db0fa4b8db0333367e9bda3ab68b8042.mpslelf 98d5dba70f80a68ee60dd912175b98b5e9f24223dca50c12997dc691300afed4Virustotal results 41.94%Mirai