URLhaus Database

You are currently viewing the URLhaus database entry for http://103.130.214.71:4949/binss/zyre.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3813081
URL: http://103.130.214.71:4949/binss/zyre.m68k
URL Status:flame Online (spreading malware for 16 hours, 42 minutes)
Host: 103.130.214.71
Date added:2026-04-06 17:27:45 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-04-06 17:28:20 UTC to hm-changed{at}vnnic[dot]vn)
Tags:elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-07n/aelf 9d380030b3d2b1fb1194e7af9fa12a4443fabc9bd1a2d0036efc05e68888313an/aMirai
2026-04-06n/aelf e01323e7dea84407cd4bad322faa3e2c2d7c2c797d488f0cc29b9cc6e1009176n/aMirai
2026-04-06n/aelf 22436a2fd3d690e4ea08150fe3c2b373e9e4cb194f80c2c0eb292739dcc7ae50n/aMirai