URLhaus Database

You are currently viewing the URLhaus database entry for http://103.20.102.84/spc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569017
URL: http://103.20.102.84/spc
URL Status:Offline
Host: 103.20.102.84
Date added:2025-06-21 19:48:08 UTC
Last online:2025-08-05 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-21 19:49:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 15 days, 3 hours, 34 minutes Bad (down since 2025-08-05 23:23:32 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-05n/aelf ae7f4dd7ff7cc7f64216b92e26366797247a61e47e0524433284613304b14e78n/aMirai
2025-08-01n/aelf b140153ae72b817e8c02e01b07bdf028dd037ea048ec0eacd6fd3b512de32775n/aMirai
2025-07-16n/aelf 0a98663b7491ec8b10c522a104bc1f211e11cad50cf0ee34e106393bb7d85f80n/aMirai
2025-07-07n/aelf 0deb48257690004a8216ab8166918bd736bd3022f36b52523b7e55a100ed24ddn/aMirai
2025-06-26n/aelf 6075c80a7ada9ccb2bc15808af49eb30e5229e4b5299dc49f843543a2b1bc0c0Virustotal results 30.16%Mirai
2025-06-23n/aelf 288aca4209e55225a374faae6851f651fc16fd09329449c20cb57671a300a52en/aMirai
2025-06-21n/aelf f9ddecc84d2aa6574ebdb084f7d2b46ddd3200a6f22156a5faf1337ac733ebc5n/aMirai