URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.142.252/bins/morte.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3487843
URL: http://176.65.142.252/bins/morte.arm
URL Status:Offline
Host: 176.65.142.252
Date added:2025-03-24 05:11:08 UTC
Last online:2025-04-10 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-03-24 05:12:08 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:16 days, 22 hours, 24 minutes Bad (down since 2025-04-10 03:36:56 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-09morte.armelf 28160bf93c530f29debe7ee5823d054fce00c656488484243b3df562522bba4bn/aMirai
2025-04-09morte.armelf b46046f97c237eefd42e123ada8918809c1e75295d3a18b683aab4d89b9ce961Virustotal results 23.81%
2025-04-08morte.armelf 0f148c28777592f0a3cc1dbf1b0b8e59c1d02318049008242d5d22aad9fd2dbbVirustotal results 23.81%Mirai
2025-04-07morte.armelf 0d0ae699f8037d178299b083c10629509468f99370c959d9bc1c86ad2555e95dn/aMirai
2025-04-06morte.armelf c856916aae5e717dd6a959fbde744f035e79326f90ff2477f9b94b80722fac98Virustotal results 23.44%Mirai
2025-03-29n/aelf d6489b5e119c9a0f5f3f64c644aa952d062983005877008b8db4b7cd0669d80aVirustotal results 20.37%Mirai
2025-03-27n/aelf d3f1ed32b1991dfc3d5cac10fd8732484d82abb0180b2daeb62f0b4d2ebe60c0Virustotal results 23.44%Mirai
2025-03-26n/aelf ab00be865d90d23f5b838d88f173b16e22c48fe651e31fb24d5a0b1db1398c1cn/aMirai
2025-03-26n/aelf de9396a649eeb7f1186b51e21253b6dac7839a0bd67f0d43a560182cd00a63c1n/aMirai
2025-03-24n/aelf 9b343186d6b9d30eeed8b2c3cc30c8315374b49c56d2dc7e888fa339f5e50ca6Virustotal results 25.00%Gafgyt