URLhaus Database

You are currently viewing the URLhaus database entry for http://89.35.130.116/00101010101001/morte.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3694993
URL: http://89.35.130.116/00101010101001/morte.arm
URL Status:Offline
Host: 89.35.130.116
Date added:2025-11-03 14:54:15 UTC
Last online:2025-11-08 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-11-03 14:55:14 UTC to abuse{at}aurorix[dot]net,ripe{at}interlir[dot]com)
Takedown time:4 days, 23 hours, 58 minutes Bad (down since 2025-11-08 14:53:31 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-08morte.armelf 11ef7882f84bc4c2bdd4af327dee278c147a32e681ba6857573bda4ef4b2a47en/aMirai
2025-11-07morte.armelf 5852fd9bd1d180beeac3eb4074956ca62a6ea9ed96f379df599f490af937e234n/aMirai
2025-11-04morte.armelf 854457830b32723de7263a9df3ad681c735bd689d97c628794bcd3d84ea08fb0n/aMirai
2025-11-03morte.armelf 1b9bc037b73e951653de45a73e77f546a1e30834f1c95998bb7f2da25ba4d28an/aMirai
2025-11-03morte.armelf b14988011dd81ebf69e2d747657b903bcb4320824e70aed62b5d09c25d637f61Virustotal results 26.56%Mirai