URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.117.162/00101010101001/morte.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3569795
URL: http://196.251.117.162/00101010101001/morte.ppc
URL Status:Offline
Host: 196.251.117.162
Date added:2025-06-24 14:39:12 UTC
Last online:2025-06-30 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-06-24 14:40:15 UTC to abuse{at}nybula[dot]com)
Takedown time:6 days, 8 hours, 9 minutes Bad (down since 2025-06-30 22:49:46 UTC)
Tags:CoinMiner mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-30morte.ppcelf 856e9cb5636752694313199f4c80a7a0577a50420e2bd7b3f6ee2252ab08345en/aMirai
2025-06-29morte.ppcelf f2d8254662030f23df7cc4cbc5be06bf0c2d2488322bc4972880c30954219591n/aMirai
2025-06-29morte.ppcelf 294e79cb67f6ba4e6616304a576cdf1ae9c6037b639e2cc0a26cd7357e7b27e6n/aCoinMiner
2025-06-29morte.ppcelf e9855aac97d286e93ea804adb347b7c44994b557394dfbc0b4b9693ac0253290n/aMirai
2025-06-25morte.ppcelf cb5bce7b4892b46bff9408c27b84bbfcd47026d53102cceaf5987d7c915a5d65Virustotal results 42.19%Mirai
2025-06-25morte.ppcelf 80643ff2a299931cd7b6af1417a97edaefc2c95e8f1fde7693e4f5422a1ca826Virustotal results 51.56%Mirai
2025-06-24morte.ppcelf 84864267a21fe1c452de656426325ea201594fa8f12dc9867ff9a8a5183859ebVirustotal results 42.19%Mirai