🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://213.232.114.14/nokillbins/telnetd which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3917235
URL: http://213.232.114.14/nokillbins/telnetd
URL Status:flame Online (spreading malware for 23 days, 12 hours, 23 minutes)
Host: 213.232.114.14
Date added:2026-09-16 06:41:15 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-09-16 06:42:33 UTC to report-abuse+xtom{at}virmach[dot]com)
Tags:gafgyt link mirai link wraith

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-10-07n/aelf d58ed4e7cf9ab3181cb59e18050cd9d4c41b334f0f07be08abe5bafed5c04069n/aMirai
2026-10-06n/aelf 51caf63a51a28343a2766566ece2c8d83725de5000c5420ccf491bb5bf2ebe39n/aGafgyt
2026-10-05n/aelf 30e0cb05a8c207c4084adaeb2906cbb8119b3d638999a73d4635e333e09cc0f6n/aMirai
2026-09-17n/aelf 941efe52eb858311653bf2c1e855555cf735896d500f11ea90aaf7e93d1faa3fn/aMirai
2026-09-16n/aelf 488cd4b95923b20587debbd1a747d9e04b85b3ff2b274e36660401e194576626n/aMirai