🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://213.232.114.14/kernal which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3916721
URL: http://213.232.114.14/kernal
URL Status:flame Online (spreading malware for 24 days, 23 hours, 11 minutes)
Host: 213.232.114.14
Date added:2026-09-15 06:08:10 UTC
Threat:Malware download Malware download
Reporter: GAYINT_DOT_ORG
Abuse complaint sent (?): Yes (2026-09-15 06:08:47 UTC to report-abuse+xtom{at}virmach[dot]com)
Tags:cowrie gafgyt link honeypot loader-payload mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-10-07n/aelf 05af569c3595b01e0724bc96c989105467952fd22a8681a716cfa22ec070d78cn/aMirai
2026-10-06n/aelf b98a0909267bca4d6296b544d4463e00f28f38099dd4504df1c6cdeac15a760fn/aMirai
2026-10-06n/aelf 85bbef10b9c34d871c3e88667b0f02b012bcb731a2f9778f204b4099c9845902n/aMirai
2026-10-05n/aelf 6c39373dfe5228575d4d49a03b3c5e8f80f77c4bb9bcc5716471fecfd936f9d7n/aMirai
2026-09-15n/aelf 085f2d517759973ab1a6e86e26295626d120194a1dac7adaaf86cdada02c8b0dn/aGafgyt