URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.152.84/sdxkzX_UXA229x.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3741932
URL: http://192.227.152.84/sdxkzX_UXA229x.mpsl
URL Status:flame Online (spreading malware for 18 days, 21 hours, 27 minutes)
Host: 192.227.152.84
Date added:2025-12-24 07:14:17 UTC
Threat:Malware download Malware download
Reporter: geenensp
Abuse complaint sent (?): Yes (2025-12-24 07:15:18 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Tags:32-bit elf mips mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11sdxkzX_UXA229x.mpslelf c16dfa007e71811fb7cee337d8713450dd2364713a467bc38c7ddb0831784ca2n/aMirai
2025-12-27sdxkzX_UXA229x.mpslelf 11935c08ce6a844ab0318f813397b1a16b5bcddff96c82e22c47e6641659ecd5n/aMirai
2025-12-24sdxkzX_UXA229x.mpslelf 96c43a2bbdd790cc4c8b2721b8364757c774c5c3b7d8617dca11eda425839089n/aMirai