URLhaus Database

You are currently viewing the URLhaus database entry for http://103.130.214.71:4949/binss/zyre.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3813077
URL: http://103.130.214.71:4949/binss/zyre.arm6
URL Status:Offline
Host: 103.130.214.71
Date added:2026-04-06 17:27:45 UTC
Last online:2026-04-07 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-04-06 17:28:19 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:22 hours, 18 minutes Good (down since 2026-04-07 15:46:39 UTC)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-07n/aelf 1fcd2ba33df1f7d312877ccc38b3874e5b0af1a04531b73bc8657cfa85c0a4a2n/aMirai
2026-04-06n/aelf 95b1e7250ba202d02ea7ff2c8e2ddb53375680d5e131bb8d0f88aee788580ea1n/aMirai
2026-04-06n/aelf 34ed3a655fdf010265730f654f29c8fb79bd9175d5c025413dbcbb2273a6fc90n/aMirai