URLhaus Database

You are currently viewing the URLhaus database entry for http://88.214.20.14/bins/tux.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3795200
URL: http://88.214.20.14/bins/tux.ppc
URL Status:flame Online (spreading malware for 5 days, 14 hours, 34 minutes)
Host: 88.214.20.14
Date added:2026-03-13 12:18:13 UTC
Threat:Malware download Malware download
Reporter: juroots
Abuse complaint sent (?): Yes (2026-03-13 12:18:36 UTC to report-abuse+xtom{at}virmach[dot]com)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19tux.ppcelf 84d2c831165ae2b9d890386755f06cb4028ec477c3e495d247fa1116e05c073bn/aMirai
2026-03-17tux.ppcelf 4208de25f695c102fde747594bd25d7c4fe1d9cacfa61f0d778fe78d1fa029a9n/aMirai
2026-03-16tux.ppcelf 4ea7ddac2f286603f650debbba565074d031b8be2f4206c2fd7ab8a772031b19n/aMirai
2026-03-16tux.ppcelf 00cb050a8c83d1250ad1d33c2a07a1c393de621d48c70f6113927a81eea52822n/aMirai
2026-03-14tux.ppcelf b988eaa416e61ec5ecefa04265e09766e3ce90be6e6b0808335e3301fddce7d1n/aMirai
2026-03-13tux.ppcelf 35fe1ff9934068d4ba7a49724c3ab2a538fec7c0921deb22e9735d6474e9371dn/aMirai
2026-03-13tux.ppcelf a4aaa14525fe034b5951da298e225689f019d8f9b3003703bb1f5957402f707fn/aMirai
2026-03-13tux.ppcelf f2ffae7077205cd33b7facb16c7859c97aa8bbbed6c573c9c71ba9940e9f2322n/aMirai