URLhaus Database

You are currently viewing the URLhaus database entry for http://156.225.31.132/c/kt2 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3604024
URL: http://156.225.31.132/c/kt2
URL Status:Offline
Host: 156.225.31.132
Date added:2025-08-15 07:16:14 UTC
Last online:2025-09-01 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-08-15 07:17:13 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:17 days, 1 hours, 48 minutes Bad (down since 2025-09-01 09:06:01 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-31n/aelf 1585347628ec4e092265d90443c142bc29878b7d3b3ce1e527e41ac407d5d30an/aMirai
2025-08-21n/aelf 8f1ac4c9ca7a488d4a62c47497e50d0934fe27a6cdaa607028d984cc2acfcaadn/aMirai
2025-08-21n/aelf ad298543ce465fab5d41f3a333a4f26494b84fda44d026c2eeca08c51363419an/aMirai
2025-08-16n/aelf 05b64f91e0330000fad73977b3f70b3e8dd830c85f234b856f1450de4c1c8915Virustotal results 55.56%Mirai
2025-08-15n/aelf 80563976a8ec265ee99b8981051b20fa9e5c957d08a6e5f39fcdbb81cadf8963Virustotal results 60.94%Mirai