URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.10/arm6.kok which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3749719
URL: http://91.92.241.10/arm6.kok
URL Status:flame Online (spreading malware for 8 days, 4 hours, 44 minutes)
Host: 91.92.241.10
Date added:2026-01-03 18:29:10 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-03 18:30:18 UTC to abuse{at}lanedo[dot]net)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11arm6.kokelf 6ae6ed76ac1b59475676b279f542a724967a0a91c61aa76cb9e2d307b1e26fa7n/aMirai
2026-01-10arm6.kokelf 4245fecaab35e03be1c28ec2e27912b1286b17936809931d540850717e00eb39n/aMirai
2026-01-09arm6.kokelf f009f10c2e38fe3d6cae25fc2e800a1e86f0e7e062149924c0e87514f82563d2n/aMirai
2026-01-05arm6.kokelf 0614fba74b502cc69626d43706c481362093d9e7e332e8f3821143b05870bce6n/aMirai
2026-01-03arm6.kokelf ba4e4c7e3d58a7315e2a9c92713157371a0b0ae776201f7d8e09c104114c88d8n/aMirai