URLhaus Database

You are currently viewing the URLhaus database entry for http://89.213.174.225/00101010101001/morte.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3622067
URL: http://89.213.174.225/00101010101001/morte.arm
URL Status:Offline
Host: 89.213.174.225
Date added:2025-09-11 19:40:16 UTC
Last online:2025-10-12 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-09-11 19:41:10 UTC to report{at}abuseradar[dot]com)
Takedown time:1 month, 0 days, 21 hours, 32 minutes Bad (down since 2025-10-12 17:13:51 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-01morte.armelf f4cf19e5c13a745e6a73b89bf7ed820d461f3dc9bb2c4380da369427785a6bf5Virustotal results 53.12%Mirai
2025-09-27morte.armelf c40bb6ff0ad98cd0b60ccf801f5d0e8400cad51c4924b82c3ff2006b4887fa71n/aMirai
2025-09-27morte.armelf 5e465e796752c9a91242984dd3304123b30978185008bfdd70a87270cfd955ben/aMirai
2025-09-25morte.armelf 3d1c06ab7a63ea3ab6fe5f226e3e0c7faa7c6926000fb048fcd041fb1d5b14a7Virustotal results 25.00%Mirai
2025-09-24morte.armelf d6dc82750a74f172475a8bf8a467967c3cbba24939c5199571cb5c14623cfc71n/aMirai
2025-09-12morte.armelf aa6450d2fbbeb15c644a6c43fe554db9dd882ee42c728c01eb38eebf441171e6Virustotal results 25.00%Mirai
2025-09-11morte.armelf c050cdc7005d924e33894c4f6d5c82e85d956aafb6291d11d93917c2f3a5d4e9n/aMirai
2025-09-11morte.armelf d9be01fe4b098f3adab77dd4f5f53a7b863d856935efe233ee1229076e443598Virustotal results 51.56%Mirai