URLhaus Database

You are currently viewing the URLhaus database entry for http://129.121.114.124/lil which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3874630
URL: http://129.121.114.124/lil
URL Status:flame Online (spreading malware for 3 days, 18 hours, 11 minutes)
Host: 129.121.114.124
Date added:2026-06-23 00:19:23 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-06-23 00:20:26 UTC to IARPOC{at}Newfold[dot]com)
Tags:mirai link sh ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-25lilsh 8ac4f5900bf7c7157534a5fd16b0561935088e15cfe25d8c35435d7d5c151a65n/aMirai
2026-06-24lilsh 839468f2fe4e29c76b2f28a2734d04294b107b4c73898718e6ea5083ec9a8063n/a
2026-06-23lilsh 88aa9ad2491a1fce729ad46829656710321f6ae79bbfc8136290cb6cdbe1f982n/aMirai
2026-06-23lilsh 2880da8ed86078f92cc1e106876aae8e6cb260b869c825daa2258846ad2c1ca8n/aMirai