URLhaus Database

You are currently viewing the URLhaus database entry for http://103.163.119.220/Aqua.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3333352
URL: http://103.163.119.220/Aqua.m68k
URL Status:flame Online (spreading malware for 1 year, 4 month, 2 days, 20 hours, 7 minutes)
Host: 103.163.119.220
Date added:2024-12-06 13:12:25 UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2024-12-06 13:13:58 UTC to hm-changed{at}vnnic[dot]vn)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-08n/aelf b528ca8099f27c4c3a97cb99857da957669900d5202d25969d63f7e66860ddfen/a
2025-02-11n/aelf 3e03dbb1f7d01ee51d5b1b49994136513cee41cc606845ad0e6ba5e0b5246538n/aMirai
2025-01-26n/aelf 1091b3be4e399898cf9e0f231d620fc515eb85e3fb0ca2084fba18d9b9f115abn/aMirai
2025-01-25n/aelf 723bc4db4f1f9451aa502aaf5bb8c597f645097bdbb7c7f07ca496ee20484cc6n/aMirai
2025-01-07n/aelf 4c2498f0f602dc58479768e045c62992c0a8f01c18a06f3e43b40d1ef59d382en/aMirai
2024-12-30n/aelf 937877a0014e44f76c89e91e73926ea8b44156c20da79d54ab5b6a2251ad8221n/aMirai
2024-12-06n/aelf 18110f785d235e450e06440028e4a31580af4ecceda0f5275630fd345e790abdn/aMirai