URLhaus Database

You are currently viewing the URLhaus database entry for http://s3o-cnc.ddns.net/00101010101001/morte.spc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3601832
URL: http://s3o-cnc.ddns.net/00101010101001/morte.spc
URL Status:Offline
Host: s3o-cnc.ddns.net
Date added:2025-08-13 14:47:26 UTC
Last online:2025-08-20 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-13 14:48:14 UTC to abuse{at}freakhosting[dot]com,report{at}abuseradar[dot]com)
Takedown time:7 days, 5 hours, 12 minutes Bad (down since 2025-08-20 20:00:29 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-16morte.spcelf b357a66a99f635dd30e4673b0975e2cfb2c012ed3e87eab663ad2816e5675702Virustotal results 57.81%Mirai
2025-08-14morte.spcelf 13bc4ce198192db350109dfb0b5f047c95656f1ca3158c12f4a81f7f6a629e92Virustotal results 57.81%Mirai
2025-08-13morte.spcelf 701a52b721267f2440f2c0a01b46993f920b48f6b1a7bac7db8b7ab784d0eb78Virustotal results 51.56%Mirai