URLhaus Database

You are currently viewing the URLhaus database entry for http://103.172.79.74/arm6?ddos which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2765218
URL: http://103.172.79.74/arm6?ddos
URL Status:Offline
Host: 103.172.79.74
Date added:2024-02-20 08:04:09 UTC
Last online:2024-03-17 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-02-20 08:05:14 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:26 days, 1 hours, 40 minutes Bad (down since 2024-03-17 09:46:08 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-16n/aelf be39f165df2b1236a4696556214a21a981190fe79e8d1db7a573fc1cf3017f80n/aMirai
2024-03-13n/aelf 5cfd2c82e8ba6d4af96602819e6e4d69e1a01e73c4313eeabda68da76792a854Virustotal results 48.78%Mirai
2024-03-02n/aelf 99080c9803c91992c9523a1e6ba816e808d957943cc01721c3553e125ef353a6Virustotal results 41.94% 
2024-03-01n/aelf 1e8b03df3af7be455ac12060292db4e0eaacf4bb2e186d11d5cfaec7dc8817e5n/a 
2024-02-27n/aelf cb1891890d985cbe0d8b8432bcb7dae9ae5e215c677b56dd6f9e5b3679d0e539n/a 
2024-02-21n/aelf 2968c577167aeef5c0bc9659c62809dfa35b11f8200e5339ddb30bae9a5e3771Virustotal results 62.30% 
2024-02-20n/aelf 02be5aec4237dba8f01527d230381dece5be5f239da331d6c8cf1615087d3034Virustotal results 53.23%Mirai
2024-02-20n/aelf eaf4a3414c0006c688d39ba4f948c21c08bf5643f1fdc90dbba864e2cb6ea094Virustotal results 46.67%Mirai