URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.10/mips.kok which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3749714
URL: http://91.92.241.10/mips.kok
URL Status:flame Online (spreading malware for 8 days, 6 hours, 1 minutes)
Host: 91.92.241.10
Date added:2026-01-03 18:29:10 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-03 18:30:18 UTC to abuse{at}lanedo[dot]net)
Tags:elf geofenced mips mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11mips.kokelf df84c58145c759e99c74fed1570dbf9089dfb200669fb911f4d60f307ef63648n/aMirai
2026-01-10mips.kokelf f624d687acb40670238554632c7f7c1403f855474f68ec5ec2d96cb916ee0610n/aMirai
2026-01-10mips.kokelf ca7123ca2ac08f281c40bcf69e7b5c5c96c20f293702486ba20440249f001e1en/aMirai
2026-01-09mips.kokelf a3381967c5dd4d39edfed3e95a2a26467fc93d25986b9dac239d009bb2057cf6n/aMirai
2026-01-05mips.kokelf 0a640b8d7602c72f6ba9f00c1e64f6849b38f4aaf1505a94e26db8e47f7fe952n/aMirai
2026-01-03mips.kokelf 3f2575b719ce6289ea9853283ea798dfa3fda8dd79481a3ea9e234a37028cf99n/aMirai