URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.65.139.42
Firstseen:2026-03-07 16:02:05 UTC
Total malware sites :21
Online malware sites :1 (5%)
Offline Malware sites :20 (95%)
Newest active malware site :2026-04-04 21:22:10 UTC
Oldest active malware site :2026-04-04 21:22:10 UTC (Age: 1 day, 3 hours, 40 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-03-07 16:02:09 176.65.139.42SBL679274AS214472 STORMINDUSTRIES- LUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-04-05 04:12:05http://176.65.139.42:8080/per.goOfflineCoinMiner Go opendir ua-wget botnetkiller
2026-04-05 04:11:16http://176.65.139.42:8080/perOfflineCoinMiner elf opendir ua-wget botnetkiller
2026-04-04 21:22:10http://176.65.139.42:8080/proxyv2.shOnlineCoinMiner opendir sh ua-wget botnetkiller
2026-04-04 16:58:19http://176.65.139.42:8080/dob.shOfflineCoinMiner opendir sh ua-wget botnetkiller
2026-04-04 16:57:21http://176.65.139.42:8080/get1.shOfflineCoinMiner opendir sh ua-wget botnetkiller
2026-04-04 16:57:21http://176.65.139.42:8080/proxy.shOfflineCoinMiner opendir sh ua-wget botnetkiller
2026-04-04 16:57:17http://176.65.139.42:8080/get.shOfflineCoinMiner opendir sh ua-wget botnetkiller
2026-04-04 02:16:10http://176.65.139.42:8080/apt0.shOfflineCoinMiner opendir sh ua-wget botnetkiller
2026-03-10 02:01:05http://176.65.139.42/bins/cool.shOfflinegeofenced mirai ext opendir sh ua-wget USA botnetkiller
2026-03-07 16:02:12http://176.65.139.42/bins/x86_64Offlineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:11http://176.65.139.42/bins/sh4Offlineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/ppcOfflineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/arm7Offlineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/x86Offlineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/arm6Offlineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/armOfflineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/spcOfflineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/mipselOfflineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:10http://176.65.139.42/bins/m68kOfflineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:09http://176.65.139.42/bins/mipsOfflineelf geofenced mirai ext ua-wget USA botnetkiller
2026-03-07 16:02:09http://176.65.139.42/bins/arm5Offlineelf geofenced mirai ext ua-wget USA botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-04-05 04:11:150b55d648d53d5865de199eb1ebd72184036aea0857cebd347b6bb8eb4ccfd714elf 
2026-04-05 04:05:278dc79c044f08ba417cbec8a4e50d71de29351e9a657121fcdad3f32041a74ff7sh 
2026-04-04 21:22:10dbd1594b55ec5174a4f9287f88f7c70e3727696f2e6aaaba372da395a97c75d6sh 
2026-04-04 16:58:19f5213422073f752fe534ac6e88b777b728dc9a85474ae577c92ec8db5692b961sh 
2026-04-04 16:57:216bfcf6860490b0952ee283f22b0f5cb536a48a6e3d8676b2596e68651929fed2sh 
2026-04-04 16:57:2149f7c39a65dd92b1d4e266d99c239253197f48d07d5c8ca2dbcb086ddc9c4751sh 
2026-04-04 16:57:1776447a4f69bb57266c1fc004b08cf69ade02d0b8db73a4e3d903b9d72732f7adsh 
2026-04-04 02:16:104f361ec950cc375e21caab543e37b463e0a5dc3d7f8d8d188f3498932cd46d5cshCoinMiner
2026-03-08 22:01:220e4bf8be4a390438e0582a3659a5348da41d2c92ea29ede35190a06c30bd0bacelfMirai
2026-03-08 03:25:50919e8fb3bc3efa6fc014c99ad056ef43eb01a1d1d00a7bcdcd2ee58e099c4a8aelfMirai
2026-03-07 16:02:127fc132b9b986683ae456c4d31b98427008584d9b0ff05684804419c7bb5ae585elfMirai
2026-03-07 16:02:1191621d0c2c33c6108dc9c6b49cd081a5bf3f6c50f3f75dbb6be80c7332f2accfelfMirai
2026-03-07 16:02:1039d68839e8a19b23d13e68bae166b5ae36596fe9831decaf68d5f1d1e2f1588delfMirai
2026-03-07 16:02:10375b90f092061faa5842a013514d17dca2f9d1f326c73aaece02759875ae1fe0elfMirai
2026-03-07 16:02:10002755d98cede8bf9bb7fa3dd4665cb35aaa8ac3b7b3ad4a81befb64622cbe55elfMirai
2026-03-07 16:02:10fd78729bffc56f9801c75072511c81bc29c530d05af5b614dcde352b6f1dbf5aelfMirai
2026-03-07 16:02:10bac8eaae693e2d7b18b917d8c52e00eeefdc9bf1014b324a0b1ab16b7f3e13efelfMirai
2026-03-07 16:02:10b7b86adb378b1c9dd37e9b34327be1c54b1ee44e122b12d6c73ea1eb49fb9913elfMirai
2026-03-07 16:02:107b9ba082df5fd5dbcba73175f3bba57ddccef25fce1512c0708367bbd0fb3859elfMirai
2026-03-07 16:02:092967f78d71dc4c0f29f1a4b8c2dd40cb0a2db03ed09e4fb0c577e7f5ea0299aeelfMirai
2026-03-07 16:02:09126bb7fe59f613f236a4e007a19b4952241162b3af3f8a41e1b2faefd6746f67elfMirai
2026-03-07 16:02:09bf113dd0b032f4abd156a6fc9af4928463b3882e554eb1fea5b4df5885b58213elfMirai