URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.110/00101010101001/morte.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3704797
URL: http://41.216.189.110/00101010101001/morte.x86
URL Status:flame Online (spreading malware for 5 days, 3 hours, 19 minutes)
Host: 41.216.189.110
Date added:2025-11-13 22:38:13 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 22:39:13 UTC to abusepoc{at}afrinic[dot]net)
Tags:elf geofenced mirai link opendir ua-wget USA x86

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18n/aelf 6b8117e57a2b87b7c07cd609d3478f8027ade35043062b6488457fe9466d8568Virustotal results 42.19%Mirai
2025-11-17n/aelf 1535023b07365bd7319f4926aaa0e9d44d99ddb8967685030580058c3e14b3eeVirustotal results 43.08%Mirai
2025-11-15n/aelf 05dc2fa3b9813e6d4840d60de74de7d951a85afc69961f5ec2f081a2031396bdn/aMirai
2025-11-14n/aelf d3f10f6d5e3c2b912e20a40579c75536930b660f07129c21bbd9788ac4efc728Virustotal results 43.08%Mirai
2025-11-13n/aelf f567d2f338d97663060bfb0d561faaa5ce9f739dab57e64e2b1658bd07c8cabfVirustotal results 44.62%Mirai