URLhaus Database

You are currently viewing the URLhaus database entry for http://88.214.20.14/bins/tux.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3795209
URL: http://88.214.20.14/bins/tux.arm6
URL Status:flame Online (spreading malware for 5 days, 20 hours, 42 minutes)
Host: 88.214.20.14
Date added:2026-03-13 12:18:16 UTC
Threat:Malware download Malware download
Reporter: juroots
Abuse complaint sent (?): Yes (2026-03-13 12:18:37 UTC to report-abuse+xtom{at}virmach[dot]com)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19n/aelf 217c1b8cb9205cde9b07790ddbf9b5e8e3f669309561618967468ab1e9503b7fn/aMirai
2026-03-18n/aelf 79b0d1a5141e8a60404ed49692042d4053a69d842770ec654e017011bbd38a50n/aMirai
2026-03-17n/aelf a8b68ecbf611d6e8d93104f48787cec1c29379990fc29d6a333cde6e433225cdn/aMirai
2026-03-16n/aelf 50bed1798938857f30aa53a63e955ff4bc1595dd01dc1f625dc23f5b58512e42n/aMirai
2026-03-16n/aelf 22565595c04aeb2ce3468ce8212164bf7747f693e1ae180c1636adabd50c1381n/aMirai
2026-03-14n/aelf f76977c251ada28c41e6d37c29d349b729a0b869476bccc94f234ef049f2a1f2n/aMirai
2026-03-13n/aelf 189181e8ff6a0747ebfc84260846f0e7d032690e2b0431d798f2ae927f65eed2n/aMirai
2026-03-13n/aelf 42da0862a113531ed2a8a3a51c0c51c22639e30780c2243a6200295aaabccde1n/aMirai
2026-03-13n/aelf 9c24a1d146159605c44a22ba16a188d7efc1f88d0d3e16124a66e1a96b34d022n/aMirai