URLhaus Database

You are currently viewing the URLhaus database entry for http://121.37.40.52/f which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3800500
URL: http://121.37.40.52/f
URL Status:flame Online (spreading malware for 4 days, 0 hours, 35 minutes)
Host: 121.37.40.52
Date added:2026-03-20 09:52:21 UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2026-03-20 09:53:11 UTC to ipas{at}cnnic[dot]cn)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-20n/aelf b9d45e38b403321e3732e180051192c50c0e8eda63de6bd67ae056c0b5ed56e4n/aMirai
2026-03-20n/aelf 62590cf0a7da7f06cb3ed3bad11e90fdff9547eac6a15007bd9b16427867819dn/aMirai
2026-03-20n/aelf 53e1a20d847c1f9a445385258ff5c192d866702a37a3e2c1cb6fa76ad874b9f2n/aMirai