URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.10/powerpc.kok which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3749713
URL: http://91.92.241.10/powerpc.kok
URL Status:Offline
Host: 91.92.241.10
Date added:2026-01-03 18:29:08 UTC
Last online:2026-01-11 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-04 06:36:10 UTC to abuse{at}lanedo[dot]net)
Takedown time:7 days, 3 hours, 24 minutes Bad (down since 2026-01-11 10:00:29 UTC)
Tags:elf geofenced mirai link PowerPC ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11powerpc.kokelf 7570d065c824764a1a3a6c65496685bfc83eff811cc1345ccb7273141950cb46n/aMirai
2026-01-10powerpc.kokelf 1bee194f57870f9d53ebc92fc873362c1ffc345efb85a5722ecbd091edf2ba91n/aMirai
2026-01-09powerpc.kokelf ec24e53b8bfddfd038c33e689b9ee31e5cfb68d57e31fd4946bad04946e35d01n/aMirai
2026-01-07powerpc.kokelf 58872b745fc26621cd3370dd7bdf2efeaa464b0649e8d3c33d7e7ff015e7d293n/aMirai
2026-01-05powerpc.kokelf 456eae96757d36fcc6ae79c6639a68f29648cfacfa8e3d0e1a007f666ad8d28en/aMirai
2026-01-04powerpc.kokelf 12eed24008138b02388e12ba2c9e01244ef66d7a993d2ce8cf906990474dce80n/aMirai