URLhaus Database

You are currently viewing the URLhaus database entry for http://109.205.213.5/resgod.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3610335
URL: http://109.205.213.5/resgod.mpsl
URL Status:Offline
Host: 109.205.213.5
Date added:2025-08-24 04:22:07 UTC
Last online:2025-09-09 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: redrabytes
Abuse complaint sent (?): Yes (2025-08-24 04:23:10 UTC to abuse{at}razinetwork[dot]com)
Takedown time:15 days, 22 hours, 11 minutes Bad (down since 2025-09-09 02:34:31 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-07resgod.mpslelf ab2e398b9d039ff05a0e2361e7b8391e1957e0252efab1ff4a37efbadcdc8357n/aMirai
2025-09-07resgod.mpslelf 00d422b87c13a11c8ae6f37f0b210207bc9605875cbf372af9f995c6a84ee7d7n/aMirai
2025-09-06resgod.mpslelf 0b16012dd73d7ea67e3b450a3a53520ccc25dfcf80308140b16d210bedc0ca9dVirustotal results 37.50%Mirai
2025-08-26resgod.mpslelf 9ee707654c2dffebf8186fe189d4cbcee5fccb0fc78e720b0e225c8f290d804en/aMirai
2025-08-24resgod.mpslelf a99601f47504decf8c1fb96c233bd51994eb4b35a9b1bc08af998570b3130e01n/aMirai
2025-08-24resgod.mpslelf 5cd58f782b4a647a98a4dbdc4293b3043485141f86a664a349e463b7c7d767b8n/aMirai
2025-08-24resgod.mpslelf fc7e9911e20f78da70f0a289fd8b99839db208a817efcbbfae7b99fa9b605c39n/aMirai