URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3766463
URL: http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.mpsl
URL Status:flame Online (spreading malware for 24 days, 14 hours, 27 minutes)
Host: 192.3.154.52
Date added:2026-01-31 08:41:32 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-02-03 18:12:11 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-16m9x7k2v8b3.mpslelf d91b528a22124afd79cdc73a5ed158f43b6c07bf90fa854aab581ce151abfec6n/aMirai
2026-02-14m9x7k2v8b3.mpslelf 9b852ed78adeea32ee3619a21d66ab158d65b4ea247e0ab42359ad148a9ae024n/aMirai
2026-02-03m9x7k2v8b3.mpslelf eb3418495b5dfb16051c2de9bb8b5bc66e9b41e1d3d99e3ea99ff6a6d6259331n/aMirai