URLhaus Database

You are currently viewing the URLhaus database entry for http://137.220.194.112/c/kt4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3531157
URL: http://137.220.194.112/c/kt4
URL Status:Offline
Host: 137.220.194.112
Date added:2025-04-30 18:29:13 UTC
Last online:2025-05-13 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-04-30 18:30:09 UTC to cs[dot]mail{at}ctgserver[dot]com)
Takedown time:13 days, 1 hours, 31 minutes Bad (down since 2025-05-13 20:01:35 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-13n/aelf cff6a937203336a0044b7ebe1800908f4f10f6558d10e7e754110d286a1a872dn/aMirai
2025-05-13n/aelf d30021ceff233c3643c60426e92e112e1bc6044c01d71ddd296231a24449fd64n/aMirai
2025-05-09n/aelf 2505e2df3b61798d0506353da677b51ee38e6a7d70581ca4ebc9e6cdfef6cdben/aMirai
2025-05-08n/aelf f75fb0c17fd3904c771656d2a82c9a37939f40f3a4542d1ab905b0e5d78f76ecVirustotal results 60.32%Mirai
2025-05-07n/aelf f259b414896c9f8006db1f03c2489bd9dd638367c44f0afda82498fe4bf9e23eVirustotal results 60.32%Mirai
2025-05-07n/aelf cb576c4c8b071cac876b8e7dcb80519082f024d06b0bc23ccb7e4c29efd05068n/aMirai
2025-04-30n/aelf 66c6e956227e60aafb70d72e491a4b3d100345494445f9c37b16949e8db6dacen/aMirai