URLhaus Database

You are currently viewing the URLhaus database entry for http://103.236.64.121/systemcl/sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3781084
URL: http://103.236.64.121/systemcl/sh4
URL Status:Offline
Host: 103.236.64.121
Date added:2026-02-19 07:32:16 UTC
Last online:2026-03-18 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2026-02-19 07:33:14 UTC to ipas{at}cnnic[dot]cn)
Takedown time:27 days, 2 hours, 7 minutes Bad (down since 2026-03-18 09:40:49 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-08n/aelf 0da9a1833bebca5fb2a7d3374fd470ea7e1735b3d415777880bbdd0e9c1ef943n/aMirai
2026-03-04n/aelf c20b51a14bf5cc81aac067b6a319e8aabef5e948b569e8e88b968fcdc4b980b1n/aMirai
2026-02-24n/aelf 7fa9b757c1826b025acd45e359260397bb863dd82d6be5c557812538cd40bb23n/aMirai
2026-02-19n/aelf 017adac4165af4bfebbec8fa8bac277b9571da71954df22457fe1fbab4985148n/aMirai