URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.110/00101010101001/morte.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3704799
URL: http://41.216.189.110/00101010101001/morte.arm5
URL Status:flame Online (spreading malware for 5 days, 4 hours, 45 minutes)
Host: 41.216.189.110
Date added:2025-11-13 22:38:13 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 22:39:13 UTC to abusepoc{at}afrinic[dot]net)
Tags:arm elf geofenced mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18n/aelf f5a3b1941dce7671aad2f0c427452a8f4643d0bd6506fd563f669c22d6db4a05Virustotal results 27.69%Mirai
2025-11-17n/aelf 23fa8bb9355902b0b4bf345280251729a4faa78dd926aabe18d32c2663e19c29Virustotal results 37.10%Mirai
2025-11-15n/aelf 48494bc2a98774569b60d6e657af2c1c781be83867fe60a12a8fa2f4279964b6Virustotal results 27.69%Mirai
2025-11-15n/aelf 7a5963641047b91e9d056037df1d88332f52916c7f9bff95931bc3b743ffd3den/aMirai
2025-11-15n/aelf 9cd34255180c429b239d9cd215d7f1193df2f1017c02a28f478a7be87bf0a6b8n/aMirai
2025-11-13n/aelf 0c3be1eaf275d8cfd7373552900f169d3a435a478d5ce5c412c1df7f7d2879aeVirustotal results 28.57%Mirai