URLhaus Database

You are currently viewing the URLhaus database entry for http://103.163.119.220/Aqua.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3333322
URL: http://103.163.119.220/Aqua.arm6
URL Status:flame Online (spreading malware for 1 year, 4 month, 2 days, 20 hours, 9 minutes)
Host: 103.163.119.220
Date added:2024-12-06 13:12:17 UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2024-12-06 13:13:58 UTC to hm-changed{at}vnnic[dot]vn)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-24n/aelf fb7118a23c859a276064ebff224168be0ad0ab57157a6a76424af7e34cf6d927n/aMirai
2025-05-09n/aelf b889953d99f776e5edebe207def28e75d07b893ee34adb11d212d8e1a6e38955n/aMirai
2025-05-08n/aelf 94ce7eb1dbd915ed1f11b4b8ac540e0bfe7752f95c9f54310361c61c0495538dn/aMirai
2025-04-16n/aelf fdeebc14ef96318c74f372d3f47b3955a1de7548bef029a1361ae0571dce4601n/aMirai
2025-03-29n/aelf d1e60d53f0d3277fb12533704e675abc5115a765e7248b1f47ea8df3006307e9n/aMirai
2025-03-15n/aelf 47cd698d493c58fe4e27f8b8e3a95f5b488aaa565179387ccae3aa8cd343785bn/aMirai
2025-03-09n/aelf 2b09913fef76759f2533e87c2197419f8ea7d793e2b027058b4f3526d75e6a46n/aMirai
2025-03-09n/aelf 9c0090ab21e48e62896e20bd9f9cc0bfae93873fcb10610fea3cdbc4e89bdf77n/aMirai
2025-02-12n/aelf daf070b1a37a27c3f751cb69ef7f43dbbe4e676b5b958137a33459005b19d1f1n/aMirai
2025-01-25n/aelf e26f2ac53f9cbc365d08c11f4745feb720a27d708ef82c422f190ade46932fcan/aMirai
2024-12-31n/aelf c9adf26f337530be726abcf83df0ef86305c9c6b2c23be85e1ed562a1b513c21n/aMirai
2024-12-06n/aelf cd8cc093d92926c4f512c7693dbaf3ebcc742b87f688dd02c6a34554ed5b0c96Virustotal results 41.27%Mirai