URLhaus Database

You are currently viewing the URLhaus database entry for http://121.37.40.52/l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3800498
URL: http://121.37.40.52/l
URL Status:flame Online (spreading malware for 4 days, 0 hours, 35 minutes)
Host: 121.37.40.52
Date added:2026-03-20 09:52:13 UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2026-03-20 09:53:11 UTC to ipas{at}cnnic[dot]cn)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-21n/aelf 8fe03f304e765f1172b0ee497b16567e5baa90cca5b15fbb8b31bfd233d4dfddn/a
2026-03-21n/aelf ca5dfdcf9fc3bbe9e3e937e89870aa01f2354717561229b37b22bb41d125d9f5n/aMirai
2026-03-20n/aelf 149182139a67e57ed056d4280ba7570b030591e87886c679b817b664d8277d3fn/a
2026-03-20n/aelf cb3110ed7e474c88b71eb8d13a2e4224ce0632dfbb5441028e49dabc0da3fd22n/aMirai