URLhaus Database

You are currently viewing the URLhaus database entry for http://121.37.40.52/w which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3800506
URL: http://121.37.40.52/w
URL Status:flame Online (spreading malware for 4 days, 0 hours, 35 minutes)
Host: 121.37.40.52
Date added:2026-03-20 09:52:24 UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2026-03-20 09:53:11 UTC to ipas{at}cnnic[dot]cn)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-24n/aelf 811ff4f27b533514bf285a56cfc9d2dce5f8bb8be61a1f06e6395f5481820ad1n/aMirai
2026-03-22n/aelf a29674fdde72fc86f9687c3a82d18f2e94cae6177b25c35e61d9a4f4e4039ed1n/a
2026-03-21n/aelf cda7bf0cf0d7fabe15cc22e32dee56ae3217e6c86176e3436a07c34f829fcd38n/aMirai
2026-03-20n/aelf f7adb6895681b0a3d24a2d0780cf9c9e719a8a3a2cf3cca46bed665610139016n/aMirai
2026-03-20n/aelf 8b9bab8ee7f102c24f82999027b4e0ae2e49c4bb3ee7b7cb620668e55c316febn/a