URLhaus Database

You are currently viewing the URLhaus database entry for http://129.121.114.124/p which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3866369
URL: http://129.121.114.124/p
URL Status:flame Online (spreading malware for 1 day, 6 hours, 49 minutes)
Host: 129.121.114.124
Date added:2026-06-17 19:18:16 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-06-17 19:19:18 UTC to IARPOC{at}Newfold[dot]com)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-18psh d6f37ef270e950ce17d63a28777ab87b1b8378585e22a4a14f1a738e1a3ff2bdn/a
2026-06-18psh 286e62f0f74ba6949f9843967a0c0873f22de5816c5fbb3f6fd0cd84828b13a8n/a
2026-06-18psh 8580b04050f13ea5787d54aa7627a31376844ef66a3d6483565f1c392c8548aen/a
2026-06-18psh 9c9cc3cd47bec052002b0f73de3b801758688fe069cb7ae49c9e1bcce820e6c5n/a
2026-06-18psh 310e0a630a2ddf7728bb695a98609cd8fdebe312b1332eecb987959707330118n/a
2026-06-17psh e681c472139934030811b3081129c35db9a7a1eddedb5e39cdc5843459fc6068n/aMirai