URLhaus Database

You are currently viewing the URLhaus database entry for http://103.20.102.84/ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569018
URL: http://103.20.102.84/ppc
URL Status:Offline
Host: 103.20.102.84
Date added:2025-06-21 19:48:08 UTC
Last online:2025-08-05 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-21 19:49:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 15 days, 3 hours, 46 minutes Bad (down since 2025-08-05 23:35:42 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-05n/aelf 00d5063c4ed84d4fd055d039da489c07e0cd10f9f7c52332cd2b5695145ffe3bn/aMirai
2025-08-01n/aelf 4f2749da72928430adf630d65cef0640f6a835ef04a91cc3eb2ba1bfa984ac8an/aMirai
2025-07-16n/aelf eb1c29b30f5dba9fcab84a6632d8b439e58b60224eed2ead55f92984f26da22en/aMirai
2025-07-07n/aelf 2c2fa6afcfcf43069579248b1e93bafd029f669e87426b929824d89d86e3ac9cn/aMirai
2025-06-26n/aelf 82e6bd3887c84122633bbc24d3dff087f5f8dcafb59e036c38235ad09e0a7617Virustotal results 30.16%Mirai
2025-06-23n/aelf 958c91412f0b7cf517b5b5bda28062a30a8615dd22804908ecee0a121d9322cen/aMirai
2025-06-21n/aelf 7ec498e55173c10b4d3043278a0c71f6e11641dbe0f7514326a5e1daaf3ed2fan/aMirai