URLhaus Database

You are currently viewing the URLhaus database entry for http://196.251.87.155/00101010101001/morte.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3697941
URL: http://196.251.87.155/00101010101001/morte.arm
URL Status:Offline
Host: 196.251.87.155
Date added:2025-11-06 08:49:26 UTC
Last online:2025-11-12 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-11-06 23:11:12 UTC to abuse{at}cheapy[dot]host)
Takedown time:5 days, 11 hours, 36 minutes Bad (down since 2025-11-12 10:47:31 UTC)
Tags:elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-11morte.armelf 70bd62673da4b4863a79b91bc5ba9a5636257685dbb981e669af123313def828n/aMirai
2025-11-11morte.armelf 676f07b21ec3361e11448aa36989bbb7e788782ee7b76e6159e170be3c31555eVirustotal results 35.38%Gafgyt
2025-11-09morte.armelf 6a7d9348e63a3d48bbf8c423f4b129de09dec30de6b648ea179b54bfdffca1ddn/aMirai
2025-11-09morte.armelf 421914f8d100f529cc4ec8bef4b5d1689137deee6964d2b2ba07a697abfc7691Virustotal results 26.56%Mirai
2025-11-08morte.armelf 1dbf137ce559af2b55c6d16727671b7799d4886816255d025a2b5be037d680e2n/aGafgyt
2025-11-08morte.armelf e40ebba75f3c7095b74fedfbd56a86628df76b9bed6621b961f3af416850e3eaVirustotal results 28.12%Mirai
2025-11-07morte.armelf 8dfa1b63873d8aa1ffb943710cca05bd9d563db6851361923103fbdc35dc98b3n/aMirai
2025-11-06morte.armelf 52a837a2153d2232a248d758f2fa6ecd9defb7a83acc87830a316c45520eb222n/aMirai