URLhaus Database

You are currently viewing the URLhaus database entry for http://157.20.32.209/bins/morte.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3632027
URL: http://157.20.32.209/bins/morte.mpsl
URL Status:Offline
Host: 157.20.32.209
Date added:2025-09-25 18:11:17 UTC
Last online:2025-10-20 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-25 18:12:13 UTC to abuse{at}intercloud-digital[dot]com)
Takedown time:25 days, 5 hours, 27 minutes Bad (down since 2025-10-20 23:39:48 UTC)
Tags:mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-06morte.mpslelf 9f142d179fbde485e13d3364d65180ee6d62449aff02e35d87447ca0f9417210Virustotal results 43.75%Mirai
2025-10-02morte.mpslelf 1a3454095d3a1d419551763c970fe2769bcdd6cfa90567c271537a0f7148290fn/aMirai
2025-09-25morte.mpslelf bfcc632ac9ed6a452bafc2e2dad68e4279f0f752e747ebba10d040b1a89011c9Virustotal results 50.00%Mirai