URLhaus Database

You are currently viewing the URLhaus database entry for http://103.163.119.220/Aqua.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3333896
URL: http://103.163.119.220/Aqua.sh4
URL Status:flame Online (spreading malware for 1 year, 4 month, 2 days, 11 hours, 56 minutes)
Host: 103.163.119.220
Date added:2024-12-06 21:23:08 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2024-12-06 21:24:12 UTC to hm-changed{at}vnnic[dot]vn)
Tags:elf mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-25n/aelf 9653215b9a91f41da6b1a278c7480fc6255ee704f4f200d47a135135efe2a060n/aMirai
2025-03-09n/aelf 1440e3a34fc6ddb288cb42b473afb00dd867e6417370a41aedbe31e49d0a3022n/aMirai
2025-02-11n/aelf 0cdc5db34bfb3936ab1cb36fc6846cc2bc9476b3a6fbd26e3bc965b83143cb58n/aMirai
2025-02-11n/aelf 8fcadedb7b5380b20081a20398af558909a8229f02f27ee58bd6e61b804ba14cn/a 
2025-01-25n/aelf a40b063e41f3e4fbca739e54066e3d1181b49657770f2ab78088cb88e16ccee0n/aMirai
2025-01-10n/aelf 15a3832c7aab5ca3074762f84eecbe610b4a702ea078967e07fd3c711b7c38b1n/aMirai
2025-01-06n/aelf ff4569db17a05a8d9221f8556bf21bff16118df1062ba4f31ebf1aebcd372851n/aMirai
2024-12-06n/aelf fce1e311c3a1dce7fd3cf9a63c1002ae8bd38f112313722ce8cbe2bd5de770b2Virustotal results 38.98%Mirai