🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://104.168.4.206/dissarm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3927810
URL: http://104.168.4.206/dissarm6
URL Status:flame Online (spreading malware for 5 days, 23 hours, 4 minutes)
Host: 104.168.4.206
Date added:2026-10-03 16:50:22 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-10-03 16:51:19 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Tags:censys elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-10-09n/aelf 1a783be1d8fe9fe4a7aedeb7ed59657f86c0080d926c09e7ba374ab9bb28e862n/a 
2026-10-07n/aelf c8fa95f0b20f773f854a1b2d8147789aae5036033faa9eb9d33444feed150c3fn/aMirai
2026-10-07n/aelf 594d0613368fa3a728bc96b756947f22adc6b03b7a0f1d82030c7f54f4c3d1bdn/aGafgyt
2026-10-05n/aelf 5e8bfc03ba47d1c00643f4ccb7d8b7a3dafcbb180d15248e74e095f205b922c9n/aGafgyt
2026-10-05n/aelf 70a09c4952159e9c80611b1128da01c5875c616311429f047338a432edb06382n/aGafgyt
2026-10-05n/aelf f7a1fa3463a548743ef3748dad33f678356bd659405e4f412d85cdabb9929e45n/aGafgyt
2026-10-04n/aelf 701cf1cac77c536622d7cae9d173bdd83e9e7b1d08c1f09b14ae39f1ddd81f4bn/aGafgyt
2026-10-04n/aelf 2614bd6433ed10049482f52bb6da315008f66db4586a896a82f372ba4eefdb09n/aMirai
2026-10-03n/aelf ed59f092ced012f8c3ececda732201c7d1f6f4a71b1a801bd1a1ac8c5e6ca597n/aGafgyt