URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.65.139.253
Firstseen:2026-04-17 20:05:06 UTC
Total malware sites :18
Online malware sites :18 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2026-04-17 20:27:12 UTC
Oldest active malware site :2026-04-17 20:05:12 UTC (Age: 9 days, 15 hours, 16 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-04-17 20:05:12 176.65.139.253SBL679274AS214472 STORMINDUSTRIES- LUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.arm5Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.dbgOnlineelf gafgyt ext mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.apkOnlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.mpslOnlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.i486Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.spcOnlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.m68kOnlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.arm7Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.arm4Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.x86Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.ppcOnlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.x64Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.i686Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.ppc440Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.arm6Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/cat.shOnlinemirai ext sh ua-wget botnetkiller
2026-04-17 20:27:12http://176.65.139.253:1212/zyre.sh4Onlineelf mirai ext ua-wget botnetkiller
2026-04-17 20:05:12http://176.65.139.253:1212/zyre.mipsOnlineelf mips mirai ext ua-wget botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-24 04:52:08005067d66ac14c10f867ab81855016e1ec2bb6e705e04afd8197cc9a5c95d524elfGafgyt
2026-04-24 00:08:478c2d8eccaf611576cadeaffa9759a46dd586d3ab7bffa10e7fc6918785dee130elfMirai
2026-04-17 20:27:12a017ca3c0a47d9896952b4517da6a8293b06dcb65ea2979616f92f6607bcfba3elfMirai
2026-04-17 20:27:1289fd6c771387c63ebe8d71d6326e10390550140a3385de99e51dc4ab9b7d068belfMirai
2026-04-17 20:27:127209fab38adb8da2ccb8f64d2b59d25647cd39a00a6fff8b7f90e28f8f43add3elfMirai
2026-04-17 20:27:128fff8e9a86dcd7df612cad060a666911cf4a1d3ed470343c40b150af8b693ad0elfMirai
2026-04-17 20:27:12c6c3ac80bb1f31bd44a9bb9a2f811f573c5a12eedce5822c659c0a4c1be3bf49elfMirai
2026-04-17 20:27:129be9baf58d9f1ab9c9dd0a0377540b53cf4c29694500e85d1a1b59c3d9f5f68belfMirai
2026-04-17 20:27:126106ce519f7e95a2cadf0ae0770ceda6a18c91873f97d1762ec655a2cd1c5881elfMirai
2026-04-17 20:27:1246d20cca8250134ee80d0eeb354d458ed189c107770fabec558a0c1de9ed4391elfMirai
2026-04-17 20:27:1284ed97a13a82a82231c5fa8bcd63d895be9e06d1f1857460aaf6ed46a28ddc80elfMirai
2026-04-17 20:27:12c74035e16ff5fdc3b373d7bc6fb0731c5f8e52de625433251fe3481ccd585876elfMirai
2026-04-17 20:27:12f29e7c0dd81dd28fe36aeb23f783e777c99d8080285795a32e2051ed0d3b4324elfMirai
2026-04-17 20:27:12540844ff88d0d343becfa5512b556daf289e8d62b7727fcfbec5be02adf69326elfMirai
2026-04-17 20:27:1244530a1f51017fa9f5ded69655d0638c0ee4498c1168030a816411c91741d006elfMirai
2026-04-17 20:27:1253bd7f7ea723b6a2854461c97e5703b2b970d843fc63d7c4bbdce67924b7354aelfMirai
2026-04-17 20:27:1243bedf7bb6ea4abad8c6a2e4a816c97230cf0e0ee461a286109f0aa61dd00be9elfMirai
2026-04-17 20:27:1253c14b83206d1c83ae672d10314ede3aaf74386d065364aed714bf0d729171e0shMirai
2026-04-17 20:27:12b76a5774a2d77ad4be7ad4b93d85ed335c67fec30155d62f3f0ff3a9e8c63d90elfMirai
2026-04-17 20:05:12b0a12cc3b6f878647c01ee35a7ddfbcd58878c83e7e04fdf92bba3cffc663593elfMirai