URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.69.254/00101010101001/morte.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3581215
URL: http://196.251.69.254/00101010101001/morte.sh4
URL Status:Offline
Host: 196.251.69.254
Date added:2025-07-11 06:52:23 UTC
Last online:2025-07-23 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-07-11 06:53:11 UTC to abuse{at}cheapy[dot]host)
Takedown time:12 days, 9 hours, 26 minutes Bad (down since 2025-07-23 16:19:46 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-19n/aelf 97d65ac4d7ef56c46367a3b4bd6ca5fd3e22c3b45f86f8f377864ec77814c5e5Virustotal results 35.94%Mirai
2025-07-15n/aelf 23e3d7a1ea1eb6be1b0ed170f1c0fe7126fcbaf5da1e1358507b5553d9da5f07Virustotal results 33.33%Mirai
2025-07-14n/aelf 4ad9938d9a5f57b31d0e91e9c03140062e8e0202cf1a757bbd7190d1cc574607Virustotal results 35.94%Mirai
2025-07-13n/aelf b320411d5a4d7ce889f7e066f33abb3af44d8a102b8f26e3317387bb0a7ea3efVirustotal results 37.50%Mirai
2025-07-13n/aelf 66732c605b041b207bb92861bd8664e4ee8783b44cfe8c055493136f3cdaa9f4n/aMirai
2025-07-12n/aelf 9b70039fe75ab1b43d9b3f1912b8ec9e631d882286703ed33d7eaf7ba7b47277n/aMirai
2025-07-12n/aelf 326244a7e8bd8fe7e9ca6ca4e77039ccde6f783d2401f53c3537cf131b57c7d2Virustotal results 34.43%Mirai
2025-07-12n/aelf b7a0965135f4a688a14b77045ebcc277ed0e40865f80f5bae95ef79ba781c74fVirustotal results 32.81%Mirai
2025-07-11n/aelf f55eb0e2df67d5652d4d2795257ea1a753ee8518431be55abd34acded7cbb644n/aMirai
2025-07-11n/aelf 5c20991e1b317088b4d7842fef0bc8b434ecc8d252c98a29c640df2425895ca4n/aMirai