URLhaus Database

You are currently viewing the URLhaus database entry for http://88.214.20.14/bins/tuxnokill.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3797438
URL: http://88.214.20.14/bins/tuxnokill.arm
URL Status:Offline
Host: 88.214.20.14
Date added:2026-03-16 20:37:07 UTC
Last online:2026-03-19 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: juroots
Abuse complaint sent (?): Yes (2026-03-16 20:37:26 UTC to report-abuse+xtom{at}virmach[dot]com)
Takedown time:2 days, 12 hours, 3 minutes Poor (down since 2026-03-19 08:41:15 UTC)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19tuxnokill.armelf ca75aa84821ab28adae9c0ccb6fd5cf318ea38c3f26984027e2e3e8b2e23303an/aMirai
2026-03-18tuxnokill.armelf 8854aa073dc916da1cfe5f9f167bb3080d4efeade4bc4e5f9caf33d7a25de842n/aMirai
2026-03-17tuxnokill.armelf 4771b1cb3f6e33666f523f9c46b2a3d3ae83f616531376bff964be7420d7f64cn/aMirai
2026-03-16tuxnokill.armelf 409c149979a739286e87e55f730410fbc14fe39a2685135b21f7cf6f51bcf466n/aMirai