URLhaus Database

You are currently viewing the URLhaus database entry for http://103.172.79.74/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2764838
URL: http://103.172.79.74/arm
URL Status:Offline
Host: 103.172.79.74
Date added:2024-02-19 21:37:14 UTC
Last online:2024-03-17 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2024-02-19 21:38:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:26 days, 11 hours, 57 minutes Bad (down since 2024-03-17 09:35:53 UTC)
Tags:elf mirai link moobot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-17n/aelf 1ed62720535f9129ce45fc8b4abb077b5e1470cb288357d2b429bbc71355cb22Virustotal results 61.90%MooBot
2024-03-13n/aelf 70cd405b91de1d9c719cda38dcd62a171a32179d486d321f8b774e8dffd2714an/aMooBot
2024-03-02n/aelf c712d9fec48fc06d72d793e8b545453b0d74d2389c81f975673ff9dde94e2372Virustotal results 41.94% 
2024-03-01n/aelf 3b7e160f74da04963f6070298f26363c09d1646dee81185752a547206faa5ca9n/a 
2024-02-27n/aelf 2a73e5ffa843b1788f1d16ae297bb4b0ae10fbebc3e78ddb9296a5c8b0659556n/a 
2024-02-27n/aelf ffe0de6c495e8bde74c35f5a545fb1ca472084f31a8d7e3b8fbffa94c93c167cn/a 
2024-02-21n/aelf c39c7dced3d6a5c19a86f9699eb15f52354d53ce2a0740a66093bc1e93cf5d27Virustotal results 59.68% 
2024-02-20n/aelf f0df1969eb7f51f46596bd6b7bd8530939fd1a8775c58713359194aea471dd26n/aMirai
2024-02-19n/aelf 1fe5cff28e668ad0fc49ed920f3a57edd9ec3f2a0f8a4794652cd80a76e8d5c9n/aMirai