URLhaus Database

You are currently viewing the URLhaus database entry for http://103.163.119.220/Aqua.arm4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3333353
URL: http://103.163.119.220/Aqua.arm4
URL Status:flame Online (spreading malware for 1 year, 4 month, 2 days, 20 hours, 7 minutes)
Host: 103.163.119.220
Date added:2024-12-06 13:12:25 UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2024-12-06 13:13:58 UTC to hm-changed{at}vnnic[dot]vn)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-07n/aelf 517a88bc6cb2c577d92219542596711382407dcc691aba10fdcb7e7c097ae068n/aMirai
2025-01-25n/aelf 62b6a50ce38774b09826189c1b6d0b399b9eabcde24f04f38f4851076eb23cb0n/aMirai
2025-01-25n/aelf 181fd6caa190d6052744804bd966e37b4a8d6569356ddc135c80d8921cb4b7bbn/aMirai
2024-12-06n/aelf 9b874602ec4c1e77afb5d9f4cb890f0a0d4a5a000f5b05567d4b01606dd6647fVirustotal results 40.62%Mirai