URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.142.252/bins/morte.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3487842
URL: http://176.65.142.252/bins/morte.sh4
URL Status:Offline
Host: 176.65.142.252
Date added:2025-03-24 05:11:08 UTC
Last online:2025-04-10 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-03-24 05:12:08 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:16 days, 23 hours, 4 minutes Bad (down since 2025-04-10 04:17:01 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-09n/aelf 37862b510e51a5a578053f62afa314c72f96f8f55001b08642ac38664a0cba11Virustotal results 36.73%Mirai
2025-04-09n/aelf 697f7efdc45fdb94dc1195c00030edb797e8d85f79fd58c341b2cd381a4b8d47n/aMirai
2025-04-08n/aelf 2a94903d79a0969e78bdf235b354041588812402da73d908d9857185045c9e5en/aMirai
2025-04-07n/aelf 4c65ec258670513d9c8cafdaa8a02f8b27c499d20a2eaff5b0cd199d25db2ef2n/aMirai
2025-04-06n/aelf 2a92b9d8018685d9d9db232c73a27476f1175cf7f62a5bc99a7d1016746c4d7fn/aMirai
2025-03-29n/aelf 2ae65015a345307cbaf5de983b7fc0afdfdb41133102a8f5332f40970f80333bVirustotal results 35.94%Mirai
2025-03-27n/aelf 254d1a4ddeb95d4680f3edcb7d3ebf4cf6b421f7f4103c3fa9c1bc1bf60c3714Virustotal results 36.51%Mirai
2025-03-26n/aelf 07d65a8aa78cfff73a31de6998d45ba1ec70d4e26be038ecbee1147caa4c3a53n/aMirai
2025-03-26n/aelf 599941bd2f00c286a73efb311c4849dbe28c0c8b57181b38ac8a8d8f07d6d0c5n/aMirai
2025-03-24n/aelf e531ea4d09e107c6eb119613aa6ddf18eed2577fb5f025882fd7d456b774c985Virustotal results 45.31%Mirai