URLhaus Database

You are currently viewing the URLhaus database entry for http://vipcncnetwork.com/bins/morte.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3586701
URL: http://vipcncnetwork.com/bins/morte.arm
URL Status:Offline
Host: vipcncnetwork.com
Date added:2025-07-21 06:30:15 UTC
Last online:2025-09-12 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-10 08:04:11 UTC to abuse{at}nybula[dot]com)
Takedown time:1 month, 29 days, 14 hours, 58 minutes Bad (down since 2025-09-18 21:30:09 UTC)
Tags:botnetdoman mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-10morte.armelf 7ed88c543f895ca2f753078b8b4ef0fc6b73069863d50ea5c27b35d87aa92deaVirustotal results 23.44%Mirai
2025-09-04morte.armelf d921387e4dba3dc4a41a605fb10e48b6950ca2eab0fc08f597a93f58ac2ac8c9Virustotal results 23.81%Mirai
2025-09-04morte.armelf e4a41e5ce00dd681bf0dccf04187c9cd2af300613a14ab84c74c8cb7604c553eVirustotal results 24.19%Mirai
2025-08-11morte.armelf 68a55de8c554359d63be31102c7020843d1610a59348a064d42d2ddc84edbf4an/aMirai
2025-08-02morte.armelf a1fa785a37fd03276effde035c81addd23415dfa8ab4ccce30e7deb806d3bb24Virustotal results 23.44%Mirai
2025-07-21morte.armelf f83b76f66452fe975e2c15145bbcd4fb24b12192eddc87b1272a9413f11b4018Virustotal results 23.44%Mirai
2025-07-21morte.armelf 1e084f768e6f712bd7a6550bfd1d6651475110be15afdaf20ea165035e41825bVirustotal results 56.25%Mirai