URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.189.110/00101010101001/morte.arc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3704802
URL: http://41.216.189.110/00101010101001/morte.arc
URL Status:flame Online (spreading malware for 5 days, 8 hours, 37 minutes)
Host: 41.216.189.110
Date added:2025-11-13 22:38:13 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-13 22:39:13 UTC to abusepoc{at}afrinic[dot]net)
Tags:arc elf geofenced mirai link opendir ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18morte.arcelf 5160c864a5c5542b4efa4b7952f1e982c95d0576cf5c149bad7e18017ef9aadaVirustotal results 53.12%Mirai
2025-11-17morte.arcelf d6e356fcc158e9d3c44888bd31d18ed0253f8b2f6e6d43dc3ccdd460f44470fbVirustotal results 51.56%Mirai
2025-11-15morte.arcelf 20b10e19db7094870b5c049dfab380a9af22bf0ab6b857d016f6e1870e0555a6Virustotal results 53.85%Mirai
2025-11-15morte.arcelf d37498c7db450f3201536869e7a89687f28c67bf15b8f488787d385459901a22n/aMirai
2025-11-14morte.arcelf c0f5ebc81a9ee665a071c886d4b449e157e0e175cf8a5091e9e34633be705684n/aMirai
2025-11-13morte.arcelf 11fe2e39b038e6ffb2d9654cf5bfafaba96177c98b8eb2704d56dc7c12c0faa0Virustotal results 53.85%Mirai