URLhaus Database

You are currently viewing the URLhaus database entry for http://14.103.145.202/rondo.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3560611
URL: http://14.103.145.202/rondo.sh
URL Status:Offline
Host: 14.103.145.202
Date added:2025-06-11 05:26:08 UTC
Last online:2025-07-01 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-06-16 04:37:10 UTC to ipas{at}cnnic[dot]cn)
Takedown time:15 days, 18 hours, 46 minutes Bad (down since 2025-07-01 23:23:53 UTC)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-29rondo.shsh 9e57ff00d9fe661d11d1d4d9406f2fe4c497c7dd569ce6e3dd42a773d3454dcan/aMirai
2025-06-28rondo.shsh 8ec76e54129ed1cf871e7faa222c66a971ba756ee2fa102117fb8825fcaafe1cn/aMirai
2025-06-25rondo.shsh 81d8941016dcc0dc42f57c6f4948c8a837b9c8c9ecc37908dfb092ac2dcf8caen/aMirai
2025-06-17rondo.shsh bc403af7d836cf5e43f4fff3ddf845332cadac552a20f1c121595971bb7f226fn/aMirai
2025-06-16rondo.shsh c88f60dbae08519f2f81bb8efa7e6016c6770e66e58d77ab6384069a515e451cn/aMirai