URLhaus Database

You are currently viewing the URLhaus database entry for http://nuklearcnc.duckdns.org/bins/morte.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3464799
URL: http://nuklearcnc.duckdns.org/bins/morte.arm
URL Status:Offline
Host: nuklearcnc.duckdns.org
Date added:2025-03-03 20:59:06 UTC
Last online:2025-03-24 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-03-23 12:57:09 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:1 month, 7 days, 6 hours, 46 minutes Bad (down since 2025-04-10 03:47:03 UTC)
Tags:botnetdomain elf gafgyt link mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-09morte.armelf 28160bf93c530f29debe7ee5823d054fce00c656488484243b3df562522bba4bVirustotal results 26.23%Mirai
2025-04-09morte.armelf b46046f97c237eefd42e123ada8918809c1e75295d3a18b683aab4d89b9ce961n/a
2025-04-08morte.armelf 0f148c28777592f0a3cc1dbf1b0b8e59c1d02318049008242d5d22aad9fd2dbbn/aMirai
2025-04-07morte.armelf 0d0ae699f8037d178299b083c10629509468f99370c959d9bc1c86ad2555e95dVirustotal results 19.61%Mirai
2025-04-06morte.armelf c856916aae5e717dd6a959fbde744f035e79326f90ff2477f9b94b80722fac98n/aMirai
2025-03-29n/aelf d6489b5e119c9a0f5f3f64c644aa952d062983005877008b8db4b7cd0669d80an/aMirai
2025-03-27n/aelf d3f1ed32b1991dfc3d5cac10fd8732484d82abb0180b2daeb62f0b4d2ebe60c0n/aMirai
2025-03-26n/aelf ab00be865d90d23f5b838d88f173b16e22c48fe651e31fb24d5a0b1db1398c1cn/aMirai
2025-03-24n/aelf 9b343186d6b9d30eeed8b2c3cc30c8315374b49c56d2dc7e888fa339f5e50ca6n/aGafgyt
2025-03-23n/aelf b5eae4525e66181d6a4c48979b143acbda90d5404e8faecc9cb48fd2e1a7723dn/aMirai
2025-03-12n/aelf fc8ffd6d03adafb0f07851131bd9b33b43deea8c247592f647d9a1d6d3ca1bc7n/aMirai
2025-03-12n/aelf a7bff61cb9edae7392ca8ce28df7cba1d45efa490efe4b829bf067d63c751fc3Virustotal results 23.44%Mirai
2025-03-11n/aelf 4a68d0f5c2ebad29b51b3a4e73ded3637342f8e75feebcc1b3e0c12793976d76n/aMirai
2025-03-11n/aelf cd7295186d6d73487af369c60cbd6330cdd06b08605f6751f87f68333e873072Virustotal results 23.81%Mirai
2025-03-09n/aelf ad9a0e8f33320a772b910b97c99c9abf77b6339986334b705cb2faad80dad566n/aMirai
2025-03-08n/aelf 1d6885a0754c9ad47d78db632bcc9062ea23105b34ec552cd63471ea1128dbc8Virustotal results 26.98%Mirai
2025-03-07n/aelf 2d8a8e332cac45a6a3c6e6ceb43ea2e17516595231845f241c29756293fc34bdVirustotal results 26.98%Mirai
2025-03-07n/aelf abd500b9bf0846da97408d1e38e864363f217e52b2926e637159f445b76a4e80n/aMirai
2025-03-06n/aelf 77c6964461df552786f59768ccc92f11a02fa049e33bb0ee40c300ab87f4cd02n/aMirai
2025-03-06n/aelf a6fbf3ff6566984190b8887ffedbf012533cc95c0d8966ab5386f547b405f3deVirustotal results 26.98%Mirai
2025-03-04n/aelf 4b6df393b34868b19776655e034886791ced311290b5a93ccb1ea541844eb6d0Virustotal results 26.98%Mirai
2025-03-03n/aelf c3d7ee8bf772eb9462e9c95ad71506463ef0a242de1e017e705763ed64fe223fVirustotal results 26.98%Mirai