URLhaus Database

You are currently viewing the URLhaus database entry for http://103.236.64.121/systemcl/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3781089
URL: http://103.236.64.121/systemcl/arm6
URL Status:flame Online (spreading malware for 14 days, 7 hours, 3 minutes)
Host: 103.236.64.121
Date added:2026-02-19 07:32:28 UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2026-02-19 07:33:14 UTC to ipas{at}cnnic[dot]cn)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-04n/aelf 9b74c3e233c6a8f3b5e76e2b537987814de5378f3b31cf9fefb1ce473d731c27n/aMirai
2026-02-24n/aelf ed5290853f112ae7042a35cd55f68fb00eae0c92da312b7b984bfccdaa21160an/aMirai
2026-02-19n/aelf 6cab3e91a084957a1d488df52a1703e091c1e9c5da44fbb8b42ad6390335499an/aMirai