URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.142.252/bins/morte.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3487839
URL: http://176.65.142.252/bins/morte.arm6
URL Status:Offline
Host: 176.65.142.252
Date added:2025-03-24 05:09:07 UTC
Last online:2025-04-10 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-03-24 05:10:11 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:16 days, 23 hours, 5 minutes Bad (down since 2025-04-10 04:15:17 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-09n/aelf 4a6433f5f79cd0461c1066d3cf3771dff1e0904437bcb1166e31233112e090edVirustotal results 36.51%Mirai
2025-04-09n/aelf 8ac1e613f5a2f871ed1d7055c890aea299ba7743e31e79433bdaa60fe2a7caaaVirustotal results 36.51%Mirai
2025-04-08n/aelf 75e953c29c75bb30c3c5e7c7d84d0261d9afd610be8d0d37d0e6592868e7feedVirustotal results 23.81%Mirai
2025-04-07n/aelf 93cbdd40048eb0e622db6f3ed6cb65c0065befed917df14c4d85754695f49d0aVirustotal results 37.50%Mirai
2025-04-06n/aelf 6984aed5d4c1ab9eae81ec3d5b5bd36e132736502ade424bb3ef6911bcb45246n/aMirai
2025-03-29n/aelf 5b17b36ce4767c2e4d4c9a4400ad29fc421031a717f638a76f4caa2a324e9180n/aMirai
2025-03-26n/aelf 8344ef0d2a9513a91168cc049d6af564ab5bec55dbb2ad04c3176e8ef1cb35e9n/aMirai
2025-03-26n/aelf 2716ecf2f3f43905e333859180279518749cbc90039e8926995ed9f5f53d4a0an/aMirai
2025-03-26n/aelf fe92e0f899dbfca1680caecee3df012984ab5b7b70b90ec32dc54397d2b287een/aMirai
2025-03-24n/aelf 9a8ca47804f256135d084d769e269bc301c8f42f2965133132466a09aa4740dfVirustotal results 39.68%Mirai