URLhaus Database

You are currently viewing the URLhaus database entry for http://103.20.102.84/debug.dbg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3568986
URL: http://103.20.102.84/debug.dbg
URL Status:Offline
Host: 103.20.102.84
Date added:2025-06-21 19:27:08 UTC
Last online:2025-08-05 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-21 19:28:12 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 15 days, 4 hours, 8 minutes Bad (down since 2025-08-05 23:36:55 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-05debug.dbgelf f2c5997c4ee8a57e5287ace7c86215b9d24a78127ade361a497d5ae64fac9c2fn/aMirai
2025-07-07debug.dbgelf 3f59de2865ff341afa86bdfb72490941a01bf804f1bf8fc1708e652bc53fff33n/aMirai
2025-06-26debug.dbgelf ac59770df12c2ed4c93cfc5386b7d38560859f46bf2e7318e62131b9148c125dn/aMirai
2025-06-23debug.dbgelf c753741f6a3ed854f91d31c890374c2c922b5099637c5b25e0581f0a180b5955n/aMirai
2025-06-21debug.dbgelf 0febf38f08c8c88570255162c856d0a2b7209c0d6a4a84530fe95aa7888c88d7n/aMirai