URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.10/arm5.kok which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3749721
URL: http://91.92.241.10/arm5.kok
URL Status:flame Online (spreading malware for 8 days, 8 hours, 29 minutes)
Host: 91.92.241.10
Date added:2026-01-03 18:29:10 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-03 18:30:18 UTC to abuse{at}lanedo[dot]net)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-11arm5.kokelf ff4abf773e3047ea1a94dbb4d2a7032a9dccc7a396cad04511d991c66dc37448n/aMirai
2026-01-10arm5.kokelf 4f8fb83b6c854a72cd242e8a8e095d75593b2834e4ea47d3e9b913a5e293ea0cn/aMirai
2026-01-10arm5.kokelf 87833480c0097231366a873fe3c90db36d558e4a50abc998dbdaec640a463f26n/aMirai
2026-01-09arm5.kokelf 94c209f2b1c09559158ddaabbc49569ad6fd899c1540f4d4cdb4c5cbb8bf7df6n/aMirai
2026-01-05arm5.kokelf c3afb7a30d142184b2f4f1b71b4840a0a7a107722330667e3fdfc3e7b8d013ecn/aMirai
2026-01-03arm5.kokelf 3756c366524f4fcb4e67ab276eb497f0eb53c73e315c57ed25962f4198d857dcn/aMirai