URLhaus Database

You are currently viewing the URLhaus database entry for http://193.143.1.32/nklm68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3422955
URL: http://193.143.1.32/nklm68k
URL Status:Offline
Host: 193.143.1.32
Date added:2025-02-01 13:38:17 UTC
Last online:2025-03-10 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-02-01 13:39:07 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 6 days, 13 hours, 52 minutes Bad (down since 2025-03-10 03:31:40 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-10n/aelf c492fcd6331bbf58b115d9b73bca526ffaafdc7940dc4a07bef529bc4e69b451n/aMirai
2025-03-06n/aelf bdadd11f7ebb796007a6c6dde13e0dbf771a681f18aa87533a1da8e10237b13dVirustotal results 39.34%Mirai
2025-03-04n/aelf 8600c3dbe9120e7b0310730a4c95b9c8d46479fe9df8bfa71332edef4db0231an/aMirai
2025-03-03n/aelf 1f1d626fd79128547c4b5945df41a79dbf5f3302d7eec1bb43728c0c26b65877n/aMirai
2025-02-25n/aelf 8b53edd65be8be2f505a557b83b1c0e5c95d4f0b8e1a5568fb6494ee00141e17Virustotal results 39.68%Mirai
2025-02-10n/aelf 5288bd0dc99091790baf2a0d254e39ff72532ac7e00cf5718fd91a0dd9bc83b2n/aMirai
2025-02-01n/aelf f15230e5d5320e0e5fc0444a3ef53cd55c267cb8e3fa6c19217c2e639c32717cn/aMirai