URLhaus Database

You are currently viewing the URLhaus database entry for http://103.176.20.59/harm4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3591791
URL: http://103.176.20.59/harm4
URL Status:Offline
Host: 103.176.20.59
Date added:2025-07-28 20:14:12 UTC
Last online:2025-08-25 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-07-28 20:15:12 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:27 days, 17 hours, 34 minutes Bad (down since 2025-08-25 13:49:18 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-22n/aelf 6073d9c704fe05bedb1f924cf5d62a0a7a9c60c5abc623f8c484ec7839e75f36Virustotal results 34.38%Mirai
2025-08-21n/aelf 65f42d596d2e3cbeb63f5b5127284c987e9255d6857fa6acd47138950b5ecfcaVirustotal results 32.81%Mirai
2025-08-15n/aelf 5526bcc71dc5bd13704fc8ab868fd921e3bc10026492491fbb412081a4e45d86Virustotal results 30.16%Mirai
2025-08-09n/aelf af38d9dce1ad7db2ad547f724b3f784083d5123a7461985350699c0b20299478n/aMirai
2025-08-05n/aelf afbd88a358ff9fe3d1689e0dad27201afcc609c16a227d8e4a5ad35f6740558bn/aMirai
2025-08-01n/aelf cbac583c6e34d928fd7018b610ef76e8a0bb02633378bba08c2d993f46e6574dn/aMirai
2025-07-28n/aelf be926b84bfce9deb71e0dc3d863d16c86319604315d2f99be7e7910d4c23967en/aMirai