URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.69.254/00101010101001/morte.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3581242
URL: http://196.251.69.254/00101010101001/morte.arm
URL Status:Offline
Host: 196.251.69.254
Date added:2025-07-11 06:52:27 UTC
Last online:2025-07-23 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-07-11 06:53:11 UTC to abuse{at}cheapy[dot]host)
Takedown time:12 days, 4 hours, 47 minutes Bad (down since 2025-07-23 11:41:08 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-19morte.armelf bbfd89b8e5789aea24faabc0ad57cfc040c2380e8cc7bd2c37bf6f9fafbed785Virustotal results 35.94%Mirai
2025-07-15morte.armelf 88844b8b2e3d2f04e5f65fc885186bd91027a968dadf7183287e7d1d7f6f291fVirustotal results 22.95%Mirai
2025-07-14morte.armelf 94fcb7a0db25f4e91eeeb6b85f4912a4621547b33929a3d404abbbb64a3581e0n/aMirai
2025-07-13morte.armelf 78ddc4958e8f3fd2545da4ccd8b2c95810d5066843c901aa2e814010fa64d016Virustotal results 21.88%Mirai
2025-07-13morte.armelf 7bfee65d8aabde87488617ff3981b09c25167ba80468828aa2dc7221e6dbd201Virustotal results 20.97%Mirai
2025-07-13morte.armelf 2cf32d1b7c409f27d80c665b308dc55202a8b644230b8ea6be279706df393dcdVirustotal results 23.44%Mirai
2025-07-12morte.armelf b1ebf1e48efd4f2116492f2e5cb2f625828e7db9919816b2c76dcbde72be27d8Virustotal results 22.22%Mirai
2025-07-12morte.armelf 738f4801fe33f50ba2de3655d1fca639bf66fb34b895a02fd24e01b72a12a3den/aMirai
2025-07-11morte.armelf 0db8d00b23fd7bdcd28400ba9e2281b3a3fac857a9ad62a7418822268e79a796n/aMirai