URLhaus Database

You are currently viewing the URLhaus database entry for http://137.220.194.112/c/kt1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3531148
URL: http://137.220.194.112/c/kt1
URL Status:Offline
Host: 137.220.194.112
Date added:2025-04-30 18:29:13 UTC
Last online:2025-05-14 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-04-30 18:30:09 UTC to cs[dot]mail{at}ctgserver[dot]com)
Takedown time:13 days, 13 hours, 54 minutes Bad (down since 2025-05-14 08:24:49 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-14n/aelf 767654de789497ee2ad7cbdd141a90a1c97fdf896c5f7daa0f74e47bf9265467n/aMirai
2025-05-13n/aelf b8256e68193fb5e4f225e5873ce177da61de23adf610b7c6321a42cce34015cen/aMirai
2025-05-09n/aelf c8fb06dd8fe117a94b21e80fdd250649130dbc2fc89cce7e52a82a20360e4796n/aMirai
2025-05-09n/aelf fc3cf89c9347ad9479bf9b3c7c6e3cc801777bb1d9db94e239a68ebe4fbfc247n/aMirai
2025-05-08n/aelf 6f79439333f5b9d3b42435173bd9deec7f63e0cd5d6012eb53077b318099e476n/aMirai
2025-05-07n/aelf b1869b62d6241a405444c814affceb6d85c8b2fa4d0327126454189858e00ca3n/aMirai
2025-05-07n/aelf 1f2b2c232654496b277f248425da32e4810d1add6ea3d7f163c2e66812906905n/aMirai
2025-05-07n/aelf 2a8029b123514454ea659c6a3bb1a933afb623d9023fe720d4e1182bdccd7629n/aMirai
2025-05-06n/aelf fe89bdd9e44d865794a18499793443d4e3dd1248bcf956ef5c23dcf79fefec63n/aMirai
2025-04-30n/aelf 9b567fb32597b792110bf9283cd8994f8e8bc3d0a3d77feb6b77a539bedde92fn/aMirai