URLhaus Database

You are currently viewing the URLhaus database entry for http://www.teamc2.duckdns.org/00101010101001/morte.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3702558
URL: http://www.teamc2.duckdns.org/00101010101001/morte.ppc
URL Status:flame Online (spreading malware for 13 days, 16 hours, 42 minutes)
Host: www.teamc2.duckdns.org
Date added:2025-11-10 18:36:42 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-11-22 21:58:13 UTC to abuse{at}vpsvault[dot]host)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-24morte.ppcelf 49b2b022e99ff6c240596010ca228174c51ca74a4ff696eb2bfd59f7940bf9c9Virustotal results 50.82%Mirai
2025-11-23morte.ppcelf ed0b869d6f5fcf7a1300e593e64432e8e5160fa15505af5f25acfca135ac603cn/aMirai
2025-11-22morte.ppcelf fe7bc142072d06558c67a121e3ae3406178241eae7248bb924e5dd859e453b47n/aMirai
2025-11-11morte.ppcelf 0d54c44eec3b371978542f5e81b0f377f1e2948cf081711fb2b798c1ccbf13ddn/aMirai
2025-11-10morte.ppcelf 855be9774710fa06cfb24af9c83bd81634455176f5455ed05dd6624d782e94a8Virustotal results 46.88%Mirai