🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://213.232.114.14/nokillbins/ntp which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3917336
URL: http://213.232.114.14/nokillbins/ntp
URL Status:flame Online (spreading malware for 23 days, 16 hours, 44 minutes)
Host: 213.232.114.14
Date added:2026-09-16 09:37:21 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-09-16 09:38:16 UTC to report-abuse+xtom{at}virmach[dot]com)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-10-07n/aelf 79470e722fcc76b61df510b3053dc645bdd7715ff719dbfab79e4f51511f278fn/aMirai
2026-10-06n/aelf be2c28842c350d43d2b3ca8822221164e190d0594be464ef80bff87c8f352207n/aMirai
2026-10-06n/aelf 76084e03973916864de9dec256d45cd25c9c0dcb0fb4b8423c9c7ee00a85e123n/aMirai
2026-10-05n/aelf a4c541461fb43666901ef0b857902d8ff393bf6a26aef748d27f724e7f81f789n/aMirai
2026-09-17n/aelf 87fed70b2634c622508ee2b28e6f58b8a431d27580f6941a6623906c6d918db5n/aMirai
2026-09-16n/aelf 1b3495dc3419da880902e570c9c27fbb7e6d3778c7edd4ffc5a35479ae196240n/aMirai