URLhaus Database

You are currently viewing the URLhaus database entry for http://160.250.134.48/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3612345
URL: http://160.250.134.48/mpsl
URL Status:Offline
Host: 160.250.134.48
Date added:2025-08-27 06:11:10 UTC
Last online:2025-09-20 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-08-27 06:12:14 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:23 days, 21 hours, 51 minutes Bad (down since 2025-09-20 04:03:59 UTC)
Tags:elf geofenced mips mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-16n/aelf fc2117cb6a4433fc0a3711ce912f4a1794741dfe467cf7c64ac9250e125b927cVirustotal results 26.56%Mirai
2025-09-11n/aelf 8c8a8f58193d087758ebf65c4c7e4e73b299f14818d6e70b6379a4182ea32a6aVirustotal results 28.12%Mirai
2025-09-09n/aelf ce994981e0120662d5e2948b3a8a840c196af8028de5bb2eaa09b479cfee8fd1Virustotal results 25.00%Mirai
2025-09-07n/aelf 3517a5c0e2f1d18f16e13dbdf62da0f48268b5e1edb5c2251c0d6dc8395be67en/aMirai
2025-09-02n/aelf 303eb333f34a2f3846afde57acb6045a6e96954da622647164184903f1d29768n/aMirai
2025-09-02n/aelf 0b0eb3705bc4cef923d383620faf8aa2831cf7f6b2b54d2ab503c8f5924169ceVirustotal results 10.94%Mirai
2025-08-27n/aelf 4332d79c1b12bd0c79885ff7d99dff4a0b8b72ab45a9f88f7c240e8ba72d87ceVirustotal results 21.88%