URLhaus Database

You are currently viewing the URLhaus database entry for http://156.225.31.132/c/kt6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3604031
URL: http://156.225.31.132/c/kt6
URL Status:Offline
Host: 156.225.31.132
Date added:2025-08-15 07:16:15 UTC
Last online:2025-09-01 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-08-15 07:17:13 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:17 days, 1 hours, 20 minutes Bad (down since 2025-09-01 08:37:51 UTC)
Tags:censys elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-31n/aelf 00224bde9a95c9babfbb57f346113ba8a4802dd4c0428d0f3aa99bef1f3ea024n/aMirai
2025-08-21n/aelf e777551ddf43422114d120eafd36cc2c53c0cc0640e11f65c794d0e9a428d4fan/aMirai
2025-08-16n/aelf 849d5cad37f4ed4cde151886e6e0d3ad83289cae0e3f3577eefc17291af9388dVirustotal results 60.94%Mirai
2025-08-15n/aelf 7bc0fe884002e1d7737a286373e66a8282f64fc600ee5ce732f8f8d3e07b13ddVirustotal results 60.94%Mirai