🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://213.232.114.14/nokillbins/telnet which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3917239
URL: http://213.232.114.14/nokillbins/telnet
URL Status:flame Online (spreading malware for 25 days, 4 hours, 15 minutes)
Host: 213.232.114.14
Date added:2026-09-16 06:41:15 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-09-16 06:42:33 UTC to report-abuse+xtom{at}virmach[dot]com)
Tags:gafgyt link mirai link wraith

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-10-07n/aelf 5003d4cf1849fc207f3023b7220800f998cc34ec416ca3525f2707711258b98an/aMirai
2026-10-06n/aelf daeb4dddaefa21f1e952b3a3e606f91d7c95955db3458730d30a0a218d005246n/aGafgyt
2026-10-06n/aelf c749b54ba8d032787dc4c990d63ceca1e43cdf49aed74775931ad3a73558cf0en/aGafgyt
2026-10-05n/aelf dcac02c71bd67e7ce708e2fad709059b817ebdde9796542ef16855de5c7b9a41n/aMirai
2026-09-17n/aelf 387d6d1bc5b00c60c64528c6b0ceb34fa7c4a83f6b8cf95f0526adb5cc57389dn/aMirai
2026-09-16n/aelf 732e796d24da151af2e4ad54d5706248aefe86686f83e5033c7ca8dd19e97954n/aGafgyt