URLhaus Database

You are currently viewing the URLhaus database entry for http://160.250.134.48/skid.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3620521
URL: http://160.250.134.48/skid.mpsl
URL Status:Offline
Host: 160.250.134.48
Date added:2025-09-09 06:08:15 UTC
Last online:2025-09-20 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-09 06:09:12 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:10 days, 22 hours, 3 minutes Bad (down since 2025-09-20 04:12:24 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-16skid.mpslelf fc2117cb6a4433fc0a3711ce912f4a1794741dfe467cf7c64ac9250e125b927cVirustotal results 26.56%Mirai
2025-09-10skid.mpslelf 8c8a8f58193d087758ebf65c4c7e4e73b299f14818d6e70b6379a4182ea32a6aVirustotal results 28.12%Mirai
2025-09-09skid.mpslelf ce994981e0120662d5e2948b3a8a840c196af8028de5bb2eaa09b479cfee8fd1Virustotal results 25.00%Mirai
2025-09-09skid.mpslelf 3517a5c0e2f1d18f16e13dbdf62da0f48268b5e1edb5c2251c0d6dc8395be67eVirustotal results 50.00%Mirai