URLhaus Database

You are currently viewing the URLhaus database entry for http://92.42.100.131/tplink/mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3856283
URL: http://92.42.100.131/tplink/mpsl
URL Status:Offline
Host: 92.42.100.131
Date added:2026-05-31 07:19:18 UTC
Last online:2026-06-25 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-31 07:20:16 UTC to alexcimadamore{at}gmail[dot]com)
Takedown time:24 days, 17 hours, 26 minutes Bad (down since 2026-06-25 00:46:19 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-12n/aelf e62822e77456614d85c60eb0d0eb80f100511dbb2969013f443a79dd60c04128n/aMirai
2026-06-10n/aelf 1291dd48e09d999600dc8b09cc56a11dc19224a2e600d171faccf7d5152bb776n/aMirai
2026-06-10n/aelf 0fe4e0ea3612811174ddce6f0c9d0c6f520e3a69830b95665c075be0cb952886n/aMirai
2026-06-10n/aelf feb90e4d6f530a60e938249c586e420e4ba05ff0acbfa6d5397a666fa454dc48n/aMirai
2026-06-09n/aelf 3e29c7115cc1a0cfdedceb010b4c31224ac78dda793813e06807842fe34166d1n/aMirai
2026-06-03n/aelf 556b7a458618f304c9de732039469781b9fc4a3515557b0aa367b4dac1d93a4bn/aMirai
2026-06-02n/aelf a8f0ca21a6d4867580b2df765ee296f71df3cea01f204848a88d2ddf565bf1aen/aMirai
2026-06-02n/aelf 56229a6050f43fd51c2a1b82dc823f4dc3ef417fe9984e90dd7ee3cb2fcd0085n/aMirai
2026-06-01n/aelf 4c8d12e5d810d705aa4b58e4ff1f5778a70b60bbd85486da1e75e422e67a282fn/aMirai
2026-05-31n/aelf ef59883df2f7d787cb605d61a765b1208975ac6f5a547d3b85b0eaff870a96bfn/aMirai