URLhaus Database

You are currently viewing the URLhaus database entry for http://103.163.119.220/Aqua.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3333316
URL: http://103.163.119.220/Aqua.arm5
URL Status:flame Online (spreading malware for 1 year, 4 month, 2 days, 20 hours, 0 minutes)
Host: 103.163.119.220
Date added:2024-12-06 13:12:15 UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2024-12-06 13:13:58 UTC to hm-changed{at}vnnic[dot]vn)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-28n/aelf d8c24ee086a65737031bd84e0b889003268eb57f28d163dd84b49487f4bcf84dn/aMirai
2025-03-18n/aelf e3d8c89608d6857f390e6fdf2ce12ec936b3c50055723219ad32e26fb1575852n/aMirai
2025-03-15n/aelf a10cc18dbeff3d46089977d3ace6f8ff627a8fdeed0f50fbb2dac48d4cf220c8n/aMirai
2025-03-09n/aelf a5f6525e6e1471bc6096d2155dfdfa024e375198c794cd99cc06c32ab3739e7bn/aMirai
2025-03-09n/aelf 1946a68fdaeb61edaa37049cfbdc44c0c0333cc2b342e133e58a651c710c1a49n/aMirai
2025-03-07n/aelf 37bd6c01c06ced32826e3c54560b22a5f05ea6c1e634f9f4d8800a5814f81a9cn/aMirai
2025-01-26n/aelf 11d9dcd9353ed261d556dff7e9fff5b83bfd0c052d6d2a43d480f2466adf9b1bn/aMirai
2025-01-08n/aelf 51c2504c5a5c878de26d4c214d137ab91778c06ed4511c88852da4aa10cd792en/aMirai
2024-12-06n/aelf 6196cb20d16b99920b874df4abd3e0a6b0becbd3355651fd2d38448933824267Virustotal results 39.06%Mirai