URLhaus Database

You are currently viewing the URLhaus database entry for http://156.225.31.132/c/kt4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3604022
URL: http://156.225.31.132/c/kt4
URL Status:Offline
Host: 156.225.31.132
Date added:2025-08-15 07:16:14 UTC
Last online:2025-09-01 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-08-15 07:17:13 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:17 days, 0 hours, 36 minutes Bad (down since 2025-09-01 07:53:30 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-31n/aelf f653ce9cbc7a8a5dd44cb19d99662350abde5ecd9391a9bdd5ba58954709dfa9Virustotal results 56.25%Mirai
2025-08-21n/aelf 0599ce4f3664b44ab7722dd907410a0da89016b2ca7740c58a328c9164464c81n/aMirai
2025-08-21n/aelf a2857043aed5028f7a3cb05ca4a511423ae3257fc9f6d7231232551c462589d8n/aMirai
2025-08-16n/aelf 81ef910fb817f2a32f146561b8fac5f887e6310cbfdae0879e9f5f7a4ec5da01Virustotal results 62.50%Mirai
2025-08-15n/aelf 659c44c9dbeed65225dc3bc79e3c6c51d1990a01f4df95dfee019c53abca8da3Virustotal results 58.73%Mirai