URLhaus Database

You are currently viewing the URLhaus database entry for http://156.225.31.132/c/kt5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3604020
URL: http://156.225.31.132/c/kt5
URL Status:Offline
Host: 156.225.31.132
Date added:2025-08-15 07:16:14 UTC
Last online:2025-09-01 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-08-15 07:17:13 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:17 days, 0 hours, 37 minutes Bad (down since 2025-09-01 07:54:54 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-30n/aelf e487182a7f176e560299f81f39703f1d1196a2469d382cc6d0190210cd88d900n/aMirai
2025-08-21n/aelf 0a24b22541001ee937effcd413b0213c9bac597aec9cabba9b9454554b595874n/aMirai
2025-08-21n/aelf aaf3d18927830ee9ea48e3c83c03037ff4fa7b2f9a9fef908a20daa934985307n/aMirai
2025-08-16n/aelf ac42da75f4fa63767596971fd4eee5211895523a22b63ce819f35d52e3ae96aaVirustotal results 58.06%Mirai
2025-08-15n/aelf 6cd7d0216a78a2d0435086b82292a9adc7d9df326b9d229afd75459c59114b66Virustotal results 58.73%Mirai