URLhaus Database

You are currently viewing the URLhaus database entry for http://78.153.140.124/b1n/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3687237
URL: http://78.153.140.124/b1n/mpsl
URL Status:Offline
Host: 78.153.140.124
Date added:2025-10-25 15:04:09 UTC
Last online:2025-11-11 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-10-25 15:05:19 UTC to abuse{at}hostglobal[dot]plus)
Takedown time:16 days, 14 hours, 39 minutes Bad (down since 2025-11-11 05:44:57 UTC)
Tags:elf gafgyt link geofenced mips ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-02n/aelf 630aa755331ab6e986384bc6e760b8aaaddea550ac2921124ff7b3e2ce142accn/a
2025-10-30n/aelf b00572c5ed68a430de8eac3dd5ab9824785ce88930ed93dbaa76f8a26f69c9e3n/aGafgyt
2025-10-30n/aelf 0b7449f4a9ee9b65b9b17f46d0e8e04a514e217ca10e9117d44a60d89fd0b3c4n/aGafgyt
2025-10-29n/aelf 877fd8c62dd739e0c1a2ba8d783732ceca531fafc73caf96a2c68e9b0fea130en/aGafgyt
2025-10-29n/aelf 8f5833a570832dfd28a1d750636c1a469ba6c62997ce3bb990f9101196d91949n/aGafgyt
2025-10-28n/aelf cd14d28faf0b5f24544833bb0f1485cdc211766f7971c5d8a56db04c672b6786n/aGafgyt
2025-10-28n/aelf b0e27837c93017deefbf8cc0f3e96e3e9a9f8ab2c11c533273419f228edabe71n/aGafgyt
2025-10-25n/aelf 97d21fc7b9723a45c7f0af8049189b0b705c44c708726effd7b6be25af4dd551n/aGafgyt