URLhaus Database

You are currently viewing the URLhaus database entry for http://mondialrelay-trajet.com/res which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3686895
URL: http://mondialrelay-trajet.com/res
URL Status:Offline
Host: mondialrelay-trajet.com
Date added:2025-10-25 10:14:15 UTC
Last online:2025-11-22 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-25 10:15:14 UTC to abuse{at}virtualine[dot]org)
Takedown time:28 days, 0 hours, 13 minutes Bad (down since 2025-11-22 10:28:14 UTC)
Tags:botnetdomain DEU geofenced mirai link opendir sh

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-16ressh 2f8b0e971474e0f90648010e79c5e7aa401f1f4e23440c10a5e09696ce8de3efVirustotal results 16.13%
2025-11-08ressh c20806aa1b652a292bbfb254c6c0285f01a2afd21ba6edbe9e53d61f9a172e65n/aMirai
2025-11-08ressh 5a4b38802ce59185df1fa14d20c94b3cd0baf0125896c2f5a17bcdac07bb5a5fVirustotal results 41.94%Mirai
2025-11-08ressh 04536a23b54005b43ecbb7188c39ce992a852e824c608a26a7837b60280ad76cVirustotal results 41.94%Mirai
2025-11-03ressh 3e4f9a5425c81fa0ee03e8edbccad2fdbf09a7d053d55fb21b06d1d3022128b2Virustotal results 45.16%Mirai
2025-10-25ressh fda65fc211748864178a49e27748eb0ab8da9be9e7962634a85c75be5f0ab8f0Virustotal results 6.45%