URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.110/00101010101001/morte.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3704795
URL: http://41.216.189.110/00101010101001/morte.sh4
URL Status:flame Online (spreading malware for 5 days, 4 hours, 45 minutes)
Host: 41.216.189.110
Date added:2025-11-13 22:38:13 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 22:39:13 UTC to abusepoc{at}afrinic[dot]net)
Tags:elf geofenced mirai link opendir SuperH ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18n/aelf a392585d6003c1ce9fe4983cb7edf01cc8d36b2f33fbda420380fb48dbc6be79Virustotal results 60.00%Mirai
2025-11-17n/aelf 896aead3bcd2c568120639f3681afcb58606df0befbd4863cdbf3625ce588f11Virustotal results 56.67%Mirai
2025-11-15n/aelf be4c1d0c512f6e088263623c04272c7b091f6dfe1762947c20e743b020248a01n/aMirai
2025-11-15n/aelf a0882db369597441beaa7031b35e49cc3d04426c9122bf55d8cf3fd80810e81dn/aMirai
2025-11-14n/aelf a1cbc4b0188f1476ed7c316842583952b48c0069473d00b1b212fac91764450fn/aMirai
2025-11-13n/aelf cdad59181881c62edcc5af0b5a3d721a8f81d69ed7ae030bb1fb12de3a74bef9Virustotal results 60.00%Mirai