URLhaus Database

You are currently viewing the URLhaus database entry for http://cnc.504.su/mipsel which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3740248
URL: http://cnc.504.su/mipsel
URL Status:flame Online (spreading malware for 2 days, 14 hours, 51 minutes)
Host: cnc.504.su
Date added:2025-12-22 15:23:21 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-22 15:24:20 UTC to abuse{at}lanedo[dot]net)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-25n/aelf 9dde8391eedecf98aa9fc30f60861ebaf910fbc81143686b6422750608341fb1n/aMirai
2025-12-24n/aelf 3413facfc2417adda146bed1d589b844a85439c40727e018bb6a4239bf77b432n/aMirai
2025-12-23n/aelf 608206076c605668e5530ce06f636cc0495a4501309f0333b5aa6f7bad5a7b8an/aMirai
2025-12-23n/aelf 09712d6752b9656be89bb42b952bc6b05b07828e445a2e5651eff2bb31f82a3cn/aMirai
2025-12-23n/aelf e40c3673eb3de0778a8a5f9827c4ac53502db150e03a1f35c243d0cfb0bf6e38n/aMirai
2025-12-22n/aelf d79395a4d78b7213be8993e568638199c704390fdbfa4330fee630d4dddc3938n/aMirai
2025-12-22n/aelf a049451baec251f9ed5adaf5e85ccbe9d8f638b315ee062b5bf8ffbb11e5b26en/aMirai