URLhaus Database

You are currently viewing the URLhaus database entry for http://137.220.194.112/c/kt5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3531154
URL: http://137.220.194.112/c/kt5
URL Status:Offline
Host: 137.220.194.112
Date added:2025-04-30 18:29:13 UTC
Last online:2025-05-13 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-04-30 18:30:09 UTC to cs[dot]mail{at}ctgserver[dot]com)
Takedown time:13 days, 1 hours, 31 minutes Bad (down since 2025-05-13 20:01:32 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-13n/aelf d1f4dd10653df6ee5cf4d7d28f0a3094afc11d11ce7030b7b55de1f72bd3aa7dn/aMirai
2025-05-13n/aelf a4c32c464f791c8b700b35a538c6eb71d6d1fb0024d7559a3050d4bf48bc740bn/aMirai
2025-05-09n/aelf 9f5aabc10550191154c78c44184fa275551c0944d6204af70e95d356f4c1f8bdn/aMirai
2025-05-09n/aelf 2bf0b5c806be0870a91358f42c463ed39605289f6c8ef8a097608166c1fa3192Virustotal results 60.32%Mirai
2025-05-08n/aelf 49a2c8181380bf6bb7774589234642c5c03b948aa3e23d71986c8b80ec38eb1bn/aMirai
2025-05-07n/aelf 77a9e5151a36fb7d1793c0da5e728bf204b29f59b0214bf7b34f2165f953d9f1n/aMirai
2025-05-07n/aelf 2e377937d18a044a33621088cfc95eda7c7dd76f972d12f7ec1f3464d1d13d8bn/aMirai
2025-05-07n/aelf 57ddc2d19c79f1b76afab850b70528eccc3cbaaac57291ef6794f44eb7efb04fn/aMirai
2025-05-06n/aelf 06953a45e8d09746458e5c04abca60324f0af3a4f7efd89ef6df0627c809b659n/aMirai
2025-04-30n/aelf 98c15c88792c615189598ae46d31a392e1e095772197b0e13da105c4369d6d1cn/aMirai