URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.10/arm.kok which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3749723
URL: http://91.92.241.10/arm.kok
URL Status:Offline
Host: 91.92.241.10
Date added:2026-01-03 18:29:13 UTC
Last online:2026-01-23 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-01-03 18:30:18 UTC to abuse{at}lanedo[dot]net)
Takedown time:20 days, 1 hours, 33 minutes Bad (down since 2026-01-23 20:04:15 UTC)
Tags:arm elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-17arm.kokelf de13418767bb55e4cd8182ae1158448deb7bfc619d2858f0e020fbe368099082n/aMirai
2026-01-13arm.kokelf 2ffa20a4410cb81c8baafac760f9e3001cb01508ef096eedd6a6994db9c60cban/aMirai
2026-01-12arm.kokelf d538d8b32caf6db4ffd172fa871c1dd0faa798c3837d2d615d68c2a163564297n/aMirai
2026-01-11arm.kokelf f762c3e51a32e4e93fd41fe3be4eac71606d84cc1372f5e100bff5b35241e74fn/aMirai
2026-01-10arm.kokelf bcbcdbf1fec75b759eb1005a06186eb73be1912e32975627536ef625b4355329n/aMirai
2026-01-09arm.kokelf ab934d3021e6527af661d0983887bbc069255fe7dee7681ffc4d21204bf15703n/aMirai
2026-01-05arm.kokelf 385d6d1f1e0740de185d59dd29e1a95ae3651c76755575683b26466aa852842en/aMirai
2026-01-03arm.kokelf 64fcc78443f443f1a15004d24e3edfa6d338e4d7aa6abf0fb0518182707f266fn/aMirai