URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.65.139.140
Firstseen:2026-08-27 07:08:05 UTC
Total malware sites :16
Online malware sites :16 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-08-27 10:05:37 UTC
Oldest active malware site :2026-08-27 07:08:16 UTC (Age: 14 hours, 39 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-08-27 07:08:16 176.65.139.140SBL679274AS219502 STORMCLOUD-AS- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-08-27 10:05:37http://176.65.139.140/bins/i586Online176-65-139-140 elf gafgyt ext ua-wget BlinkzSec
2026-08-27 10:05:37http://176.65.139.140/bins/x86_64Online176-65-139-140 elf gafgyt ext ua-wget BlinkzSec
2026-08-27 10:05:34http://176.65.139.140/bins/ppc440Online176-65-139-140 elf gafgyt ext ua-wget BlinkzSec
2026-08-27 10:05:33http://176.65.139.140/bins/i486Online176-65-139-140 elf gafgyt ext ua-wget BlinkzSec
2026-08-27 09:10:22http://176.65.139.140/bins/x86Onlineelf mirai ext ua-wget abuse_ch
2026-08-27 09:09:31http://176.65.139.140/bins/arm4Onlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:31http://176.65.139.140/bins/x32Onlineelf mirai ext ua-wget abuse_ch
2026-08-27 09:09:31http://176.65.139.140/bins/sh4Onlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:30http://176.65.139.140/bins/arm7Onlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:30http://176.65.139.140/bins/arm6Onlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:29http://176.65.139.140/bins/ppcOnlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:29http://176.65.139.140/bins/m68kOnlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:29http://176.65.139.140/bins/mipsOnlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:28http://176.65.139.140/bins/mipselOnlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 09:09:15http://176.65.139.140/bins/arm5Onlineelf gafgyt ext ua-wget abuse_ch
2026-08-27 07:08:16http://176.65.139.140/exodus.shOnlineelf gafgyt ext iot HoneyLabs

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-08-27 10:07:07a3a420313870af122bdc8ecd1780d9e38ea95e25cc8bf35c18abfd05ee645bd0elfGafgyt
2026-08-27 10:06:4528b0bd59072f8fbd9c9c460dcf066921b6e228d64fd1d0aea78d51a931edf719elfGafgyt
2026-08-27 10:06:2407bfd97e419f739258c04c8bc976ae6add8bd2936c97471642a759b0b6cc115belfMirai
2026-08-27 10:06:035086d80f6e009feaccedf2c69368ddae803e11a8d7ffaafb4b790177828abc90elfGafgyt
2026-08-27 10:05:48cdcb1f84e63d751507c306ff5469d8e2773df0da132efcfd082483aad0d50bf9elfGafgyt
2026-08-27 10:05:362907bf1549c5e18580b9faf1edd5d8f7088317af803c763240782b052336d4f2elfGafgyt
2026-08-27 10:05:3625a8d963fff24bc21a1820473c36d72f02ab5c3f8e54195b6fef781bd47cb5a9elfGafgyt
2026-08-27 10:05:33d36cff93b5c3936f33d95e76051dab320e8ee68e0a7f5e74e569ac1ee6278658elfGafgyt
2026-08-27 10:05:336e6f0e9848fb60811a8b3e909bdc2c8f196e59f73ed967f8b4fc2f01797082f6elfGafgyt
2026-08-27 10:05:24bbb85b3789dffcd64d0548b75c52647e9fec3a5192dac9da86ac9ae04cd5492delfGafgyt
2026-08-27 10:02:09194a7312e15bcb554afd95892718789be4012efd7cfb8d00b24882a910a2a9a5elfGafgyt
2026-08-27 10:01:34af94109f16e8e3967f70fe46f755a7f494b2a39c558fd7e759b7fa5496c3b4a1elfGafgyt
2026-08-27 10:00:499cca3b4a8fe06e29d4683b448dac14be142eb3b14ed7a5b5ccf8bcf37ce80318elfGafgyt
2026-08-27 09:10:2107bfd97e419f739258c04c8bc976ae6add8bd2936c97471642a759b0b6cc115belfMirai
2026-08-27 09:09:153702adbc131fd77738189af8c6fb3c2f89c8ac65c1499e06fde55b7df0bf9689elfGafgyt
2026-08-27 07:08:15bcde5249b6e351e8beacc988662c77435803709d4de448daf21d8c1d9506dd79shGafgyt