URLhaus Database

You are currently viewing the URLhaus database entry for http://103.20.102.84/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3569029
URL: http://103.20.102.84/arm6
URL Status:Offline
Host: 103.20.102.84
Date added:2025-06-21 19:48:13 UTC
Last online:2025-08-05 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-06-21 19:49:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 15 days, 3 hours, 28 minutes Bad (down since 2025-08-05 23:17:59 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-04n/aelf b78a40c5cfe60dac573574bc6d166596fe6053f24646bbf65468d8272bf82f90n/aMirai
2025-08-01n/aelf a2fbe76e8cc2a23e2ff9fbd3f12ba1cb2507782b0ae27052f7dd55078dab6565n/aMirai
2025-07-16n/aelf 1c3dee8f94f7f390ee8a44cd3653d941a979af06517f4d9b357aea0062d78e49Virustotal results 51.56%Mirai
2025-07-07n/aelf 9ea960f68bd765a8aec60540dc8663da86540ff3b07b1faf6ca01f8245ff41cdn/aMirai
2025-06-26n/aelf f7c507aea3abff7eedd281b30660e96d89f52cf9636dd42aa780de5331e8dba8n/aMirai
2025-06-23n/aelf 363e6f983f437cfd01113eb77324a0082b032e96e1f18413c995cc0b212ecd40n/aMirai
2025-06-21n/aelf 3a21fe87bd7dfb9791f7088fe577c13acb76bc8a0f6430fab00619a0ef625eabn/aMirai