URLhaus Database

You are currently viewing the URLhaus database entry for http://162.248.53.119:8000/kwthread which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3584186
URL: http://162.248.53.119:8000/kwthread
URL Status:Offline
Host: 162.248.53.119
Date added:2025-07-16 02:30:35 UTC
Last online:2025-08-24 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-07-16 02:40:13 UTC to arin{at}gigas[dot]com,hugo[dot]deandres{at}gigas[dot]com)
Takedown time:1 month, 9 days, 12 hours, 18 minutes Bad (down since 2025-08-24 14:58:32 UTC)
Tags:Merlin opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-08n/aelf b6bcc8a2e69f05282cf0519271dd7661843d715025312dce2abaa177839c72c2n/aMerlin
2025-08-06n/aelf bd088befb92672cbbf1488fca04bc00eaaf3aa3d34068152ee37b9f0142a7227n/aMerlin
2025-07-30n/aelf ff663d0a204e14989afa5aa2d2f16063b0dec9bd8c78f837c7096515cffbed13n/aMerlin
2025-07-30n/aelf 4acee430374ad10390119a5fa7e82ec15c831748c2f227dd99b1d49373b31a74n/a
2025-07-28n/aelf b42ac944fe347ac2a37546facacc87bd912c90aba4fb21b54c977bb8629147d5n/aMerlin
2025-07-23n/aelf f28501b90adee4c16d086a6f3258f0980ab223907e6fb63490ec256ec44f4a53n/aMerlin
2025-07-21n/aelf 359dcc090cfda8dfc037b4ec811a45062181e7f6c9d78ed348c74413d9db3de0n/aMerlin
2025-07-16n/aelf 755906ab791dc82b1794492126f8253f8a8784d13ed19bc09468296b0e2f7472n/aMerlin