URLhaus Database

You are currently viewing the URLhaus database entry for http://88.214.20.14/bins/tuxnokill.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3797437
URL: http://88.214.20.14/bins/tuxnokill.x86
URL Status:flame Online (spreading malware for 2 days, 12 hours, 13 minutes)
Host: 88.214.20.14
Date added:2026-03-16 20:37:07 UTC
Threat:Malware download Malware download
Reporter: juroots
Abuse complaint sent (?): Yes (2026-03-16 20:37:25 UTC to report-abuse+xtom{at}virmach[dot]com)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19n/aelf be902e86ec68515e23a3387a21e80d098d258223ce562598c27ee6d89b83ff2bn/aMirai
2026-03-17n/aelf 1708621d7ed75e711d925cb96436fa5a5403c29c5b71b5159170114c532962b5n/aMirai
2026-03-16n/aelf a9c595b2c94cbcd3c93fdc72705b502080848f45f41a4142ad77c5a5f4326b0bn/aMirai