URLhaus Database

You are currently viewing the URLhaus database entry for http://103.163.119.220/Aqua.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3333317
URL: http://103.163.119.220/Aqua.ppc
URL Status:flame Online (spreading malware for 1 year, 4 month, 2 days, 15 hours, 49 minutes)
Host: 103.163.119.220
Date added:2024-12-06 13:12:15 UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2024-12-06 13:13:58 UTC to hm-changed{at}vnnic[dot]vn)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-09Aqua.ppcelf d0cee39543cbb5eb73ff62c3eb97900ad066d104b5d18d09d139c660183ff8d6n/aMirai
2025-04-20Aqua.ppcelf 9630454318c2740b7e7d8e344d50a90d230bdaa6d134c561f8ae9176b3b2f186n/aMirai
2025-03-09n/aelf 95f28d9cd60eb259654f5f95f4ffb80160f7905fca8d9d0a1d4cc4f24562ac43n/aMirai
2025-03-07n/aelf f4bef7691790ef38078038e3564016d97528cb1c4b885f55074dc5821f676e55n/aMirai
2025-01-25n/aelf e87d8a6ec50bfa7af127c729d69f41bca94e0a1fcb3f45b8e7de6da60d7924d5n/aMirai
2025-01-25n/aelf b964d4aa3ac23707128c855ba16c9db60a3a8d0c1f238e03dc4eb5e6a0bd8037n/aMirai
2025-01-17n/aelf 56ac5d98aa8793dfe729d49ff98d8a9812ad1f1fdf7b4c16e55e0350d32d602cn/aMirai
2025-01-10n/aelf 01c5431318637b541465badeebd6e7c83b66ac6e02f5d46abaf2f8d59a147e55n/aMirai
2024-12-06n/aelf 1bb61516ab526b599de0916d5380ef34792f66fa40e10ab96119cd06bc2f17f6Virustotal results 43.75%Mirai