URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.110/00101010101001/morte.mips which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3704796
URL: http://41.216.189.110/00101010101001/morte.mips
URL Status:flame Online (spreading malware for 5 days, 3 hours, 20 minutes)
Host: 41.216.189.110
Date added:2025-11-13 22:38:13 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 22:39:13 UTC to abusepoc{at}afrinic[dot]net)
Tags:elf geofenced mips mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18morte.mipself 2d4a96fdb4a0dcc89308bc1d799f8a4d3509bfcb381c8525b321b6b7bcab9aa0Virustotal results 39.06%Mirai
2025-11-17morte.mipself 25b7ec1b2927604b6943d5167b0d4518ee4ac8407d55c8b814bda4b7fbb8ccb6Virustotal results 40.00%Mirai
2025-11-16morte.mipself 7ab71d3eea8507eac54876fd314c45baae3a10bf70a0fe2cc218dcde1bcea5e2Virustotal results 39.34%Mirai
2025-11-15morte.mipself 7448183674167347f1123070d12359164d5c896e23eb58cf66de17027e0ff078n/aMirai
2025-11-15morte.mipself e547e9e639a551e64960b74a64cb0349788150d454538f980cefe50e33aa069fn/aMirai
2025-11-14morte.mipself 21782793f8c22a44cc00c57d28fc4468469c09be0879bae0921e423ff5a55f17n/aMirai
2025-11-13morte.mipself 9e1ef83ee62e92314c5c446dcdcbdf343329f7329feb226d4950de5d0d7da138Virustotal results 40.00%Mirai