URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.10/arm5.kok which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3749721
URL: http://91.92.241.10/arm5.kok
URL Status:Offline
Host: 91.92.241.10
Date added:2026-01-03 18:29:10 UTC
Last online:2026-01-23 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-03 18:30:18 UTC to abuse{at}lanedo[dot]net)
Takedown time:19 days, 8 hours, 31 minutes Bad (down since 2026-01-23 03:01:25 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-13arm5.kokelf 8e646a1ec0ae9ef84648d3de70787c8d78fe6985c487751a57408d0ac609aeddn/aMirai
2026-01-12arm5.kokelf b3bab1e4be915a7920afe13c50846b43e1491cb18042e19e0e1eafc50ea17c63n/aMirai
2026-01-11arm5.kokelf ff4abf773e3047ea1a94dbb4d2a7032a9dccc7a396cad04511d991c66dc37448n/aMirai
2026-01-10arm5.kokelf 4f8fb83b6c854a72cd242e8a8e095d75593b2834e4ea47d3e9b913a5e293ea0cn/aMirai
2026-01-10arm5.kokelf 87833480c0097231366a873fe3c90db36d558e4a50abc998dbdaec640a463f26n/aMirai
2026-01-09arm5.kokelf 94c209f2b1c09559158ddaabbc49569ad6fd899c1540f4d4cdb4c5cbb8bf7df6n/aMirai
2026-01-05arm5.kokelf c3afb7a30d142184b2f4f1b71b4840a0a7a107722330667e3fdfc3e7b8d013ecn/aMirai
2026-01-03arm5.kokelf 3756c366524f4fcb4e67ab276eb497f0eb53c73e315c57ed25962f4198d857dcn/aMirai