URLhaus Database

You are currently viewing the URLhaus database entry for http://158.51.126.131/lilin.sh which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569764
URL: http://158.51.126.131/lilin.sh
URL Status:Offline
Host: 158.51.126.131
Date added:2025-06-24 09:53:05 UTC
Last online:2025-09-07 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-06-24 09:54:12 UTC to abuse{at}hostodo[dot]com)
Takedown time:2 months, 14 days, 16 hours, 43 minutes Bad (down since 2025-09-07 02:37:35 UTC)
Tags:gafgyt link mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-30lilin.shsh 8dd0db78973bb8e890eda9cea0eeb79a28f7201caf5457f88afc77c991bdbd77n/aGafgyt
2025-08-16lilin.shsh c2490973c357f0586349a22fd890577c53f0ecf42e537abe103c41d5154c2b98Virustotal results 32.26%Mirai
2025-07-07lilin.shsh 9d37a0fb6e95aa4fe1ef4cfa8e328222cf23d97a42e676d5f13ed6877fc0e009n/aMirai
2025-06-26lilin.shsh 31f7d4b5eb7d9b393564f8c2e99e585ebbf59e626b809c9d0ba672d388e72fa4n/aMirai
2025-06-25lilin.shsh 26095a31fcdc1b465cf858f3c6fae3f39bb1f9e38e7534c6b235d4c7bc659c3an/aMirai
2025-06-24lilin.shsh bf84b95a3561ffa3dd65a94b28891a12aed0fecfcf79b9bcaea58a1cfb9dbd60Virustotal results 30.65%Mirai