URLhaus Database

You are currently viewing the URLhaus database entry for http://103.176.20.59/skid.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3610834
URL: http://103.176.20.59/skid.mpsl
URL Status:Offline
Host: 103.176.20.59
Date added:2025-08-24 14:55:28 UTC
Last online:2025-09-26 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-08-24 14:56:18 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 2 days, 19 hours, 35 minutes Bad (down since 2025-09-26 10:31:33 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-21skid.mpslelf e4acbf0a1448e928ea7714cf90692001c454b37d78b13a955f475568b36bbaecVirustotal results 23.44%Mirai
2025-09-17skid.mpslelf fc2117cb6a4433fc0a3711ce912f4a1794741dfe467cf7c64ac9250e125b927cVirustotal results 26.56%Mirai
2025-09-11skid.mpslelf 714d5510deeefc8f0e36609b1713fe7acf20cdb661eee78bc69723f54f4d46f4n/aMirai
2025-09-10skid.mpslelf 8c8a8f58193d087758ebf65c4c7e4e73b299f14818d6e70b6379a4182ea32a6aVirustotal results 28.12%Mirai
2025-09-10skid.mpslelf ead4a102bde23a81c6e93a337d01892c68f3f67882d104bc90c46a2bca5f2bceVirustotal results 28.12%Mirai
2025-09-09skid.mpslelf ce994981e0120662d5e2948b3a8a840c196af8028de5bb2eaa09b479cfee8fd1Virustotal results 25.00%Mirai
2025-09-04skid.mpslelf cbdaa444bc8c2f8c5bdad87cdfd4cea20d87aee0214fdf0ea8ab697670e9177cVirustotal results 34.43%
2025-09-02skid.mpslelf 0b0eb3705bc4cef923d383620faf8aa2831cf7f6b2b54d2ab503c8f5924169ceVirustotal results 10.94%Mirai
2025-08-24skid.mpslelf f78466c5c04ef666db6d4b80143a769fd186565a3035bfcb19d6a6a92418b2feVirustotal results 25.00%