URLhaus Database

You are currently viewing the URLhaus database entry for http://88.214.20.14/bins/tux.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3795208
URL: http://88.214.20.14/bins/tux.sh4
URL Status:Offline
Host: 88.214.20.14
Date added:2026-03-13 12:18:15 UTC
Last online:2026-03-19 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: juroots
Abuse complaint sent (?): Yes (2026-03-13 12:18:36 UTC to report-abuse+xtom{at}virmach[dot]com)
Takedown time:5 days, 20 hours, 42 minutes Bad (down since 2026-03-19 09:00:45 UTC)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19n/aelf f7427d1ceea9ba34056691a20a10716dc14fbaf38759146e15cc18f7a3ead600n/aMirai
2026-03-18n/aelf e4b5740a806c79b10a608332c6a1099780303b0b82d3b4be122734af28ae8314n/aMirai
2026-03-17n/aelf f0cff8b4a2ae62b125606d4fa5769a083649d33a34ec33e4ea245cd7a29e35d0n/aMirai
2026-03-16n/aelf 8584724522a847f044b69bfe88a4d615839da4549dcf6d14571592f3857f3045n/aMirai
2026-03-16n/aelf a8c55e579790c6ffe5239b837488f71456bde46f3b89a3ec31bf37aa9ebd2686n/aMirai
2026-03-14n/aelf 2e8c0d6dc54e6310e4aa63f49e31ba48cd2d42c5124e703a9bc4b0276f635c3bn/aMirai
2026-03-13n/aelf 07228022677dfb7e88734540608fb757da7b26ea4de00fe7554b0b389c501bcen/aMirai
2026-03-13n/aelf 327265f8d359f8c76ad271b25d3e7f07c847be3837dd17e86c0682000aa35309n/aMirai
2026-03-13n/aelf fc4831705703eac95b86d474267d89af3d85e24e10d6ebfa56ac2dfa84258ff9n/aMirai