URLhaus Database

You are currently viewing the URLhaus database entry for http://157.20.32.209/bins/morte.arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3632007
URL: http://157.20.32.209/bins/morte.arm6
URL Status:Offline
Host: 157.20.32.209
Date added:2025-09-25 18:11:11 UTC
Last online:2025-10-20 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-25 18:12:13 UTC to abuse{at}intercloud-digital[dot]com)
Takedown time:25 days, 4 hours, 11 minutes Bad (down since 2025-10-20 22:24:01 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-06n/aelf b3cd17f0afa885b377f8b04679e75f7f0827189f0b3f025a3814d156b4db1c38Virustotal results 33.33%Mirai
2025-10-02n/aelf 050da097f8802963451227a3a1fa7bf4369fdd8fa113ef1a26cf1c37bdade502n/aMirai
2025-09-25n/aelf 8ec74941b42b3c681b84f7f11955eb67460cba17993b4eda5d4a9d56acc14fb3Virustotal results 26.92%Mirai