URLhaus Database

You are currently viewing the URLhaus database entry for http://137.220.194.112/c/kt3 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3531149
URL: http://137.220.194.112/c/kt3
URL Status:Offline
Host: 137.220.194.112
Date added:2025-04-30 18:29:13 UTC
Last online:2025-05-13 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-04-30 18:30:09 UTC to cs[dot]mail{at}ctgserver[dot]com)
Takedown time:13 days, 0 hours, 58 minutes Bad (down since 2025-05-13 19:29:03 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-13n/aelf 1a4bb616ff418385071bce7f97e078eb488faddb8eb14ad9625de68a1ea158b7n/aMirai
2025-05-09n/aelf 2acfee79e070bfe9dcee8dd48ef012b3a068fe65691addff6c9b6f28568d4b14n/aMirai
2025-05-08n/aelf af7e66b0512c1eac9b18e6636b891bdfaa1c430ad5f98046c5d9af57f356d068Virustotal results 57.14%Mirai
2025-05-07n/aelf 4e6fba35d80beac15636ff688cb5fb26b87572c7e46e624b41359903c7332db3n/aMirai
2025-05-07n/aelf fb810daa8b0919bde2a4d62f36530e963f13236319d79d2da80075145888e00fn/aMirai
2025-05-06n/aelf b06f51895f371452057a68ffe55d8a11c6656bb56729f008f1fb1bdc8fc1bf2dn/aMirai
2025-04-30n/aelf 55ea56a88c274e70ab5cb3b274f71cdaf84045a0c335744cb6281abb0ce569den/aMirai