URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.110/00101010101001/morte.x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3704800
URL: http://41.216.189.110/00101010101001/morte.x86_64
URL Status:flame Online (spreading malware for 5 days, 4 hours, 47 minutes)
Host: 41.216.189.110
Date added:2025-11-13 22:38:13 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 22:39:13 UTC to abusepoc{at}afrinic[dot]net)
Tags:elf geofenced mirai link opendir ua-wget USA x86

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18n/aelf 5fa965225e35c97914d3d6b771c39e2971d4b8914609922852fe1efbc9a6010dVirustotal results 39.68%Mirai
2025-11-17n/aelf 1299a84282f2f96e29acbe51f1822ba5860b14b4b61aae7b0cf0a045677413f3Virustotal results 40.62%Mirai
2025-11-15n/aelf 13c4df50e1cac452500fa11a328b86e70414281a294016b02151dff0152faf5cVirustotal results 38.46%Mirai
2025-11-15n/aelf 2cc524c64207ff66b28d14f23da1bbd9e9c0c6fc5f42023f657b10ac4283cf92n/aMirai
2025-11-13n/aelf 20a56e4d75bd9aa610390ff724a232ccd3a328db5ea75c5f1f3bc447c04352b4Virustotal results 39.06%Mirai