URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.65.139.9
Firstseen:2026-01-31 16:43:05 UTC
Total malware sites :39
Online malware sites :12 (31%)
Offline Malware sites :27 (69%)
Newest active malware site :2026-05-12 19:09:23 UTC
Oldest active malware site :2026-05-12 19:07:14 UTC (Age: 1 day, 17 hours, 3 minutes)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-01-31 16:43:12 176.65.139.9SBL679274AS214472 STORMINDUSTRIES- LUyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-05-12 19:09:23http://176.65.139.9/FBI.m68kOnlineelf gafgyt ext m68k mirai ext ua-wget botnetkiller
2026-05-12 19:09:23http://176.65.139.9/zorgy.shOnlinegafgyt ext sh ua-wget botnetkiller
2026-05-12 19:09:23http://176.65.139.9/FBI.i686Onlineelf gafgyt ext mirai ext ua-wget x86 botnetkiller
2026-05-12 19:08:22http://176.65.139.9/FBI.mipselOnlineelf gafgyt ext mips mirai ext ua-wget botnetkiller
2026-05-12 19:07:28http://176.65.139.9/FBI.mipsOnlineelf gafgyt ext mips mirai ext ua-wget botnetkiller
2026-05-12 19:07:19http://176.65.139.9/FBI.sh4Offlineelf gafgyt ext mirai ext SuperH ua-wget botnetkiller
2026-05-12 19:07:19http://176.65.139.9/FBI.armOnlinearm elf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-12 19:07:19http://176.65.139.9/FBI.arm7Onlinearm elf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-12 19:07:19http://176.65.139.9/FBI.arm6Onlinearm elf gafgyt ext mirai ext ua-wget botnetkiller
2026-05-12 19:07:19http://176.65.139.9/FBI.x86_64Onlineelf gafgyt ext mirai ext ua-wget x86 botnetkiller
2026-05-12 19:07:19http://176.65.139.9/FBI.ppcOnlineelf gafgyt ext mirai ext PowerPC ua-wget botnetkiller
2026-05-12 19:07:14http://176.65.139.9/FBI.x86Onlineelf mirai ext ua-wget x86 botnetkiller
2026-05-12 19:07:14http://176.65.139.9/FBI.arm5Onlinearm elf gafgyt ext mirai ext ua-wget botnetkiller
2026-01-31 16:45:17http://176.65.139.9/bins/87sbhas6as.arm6Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:44:17http://176.65.139.9/bins/beeOfflinesh ua-wget BlinkzSec
2026-01-31 16:44:17http://176.65.139.9/bins/gpon.shOfflinesh ua-wget BlinkzSec
2026-01-31 16:44:11http://176.65.139.9/bins/87sbhas6as.mipsOfflineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:44:11http://176.65.139.9/bins/akiraOfflinesh ua-wget BlinkzSec
2026-01-31 16:44:11http://176.65.139.9/bins/a.shOfflinesh ua-wget BlinkzSec
2026-01-31 16:44:11http://176.65.139.9/bins/weed.shOfflinesh ua-wget BlinkzSec
2026-01-31 16:44:11http://176.65.139.9/bins/w.shOfflinemirai ext sh ua-wget BlinkzSec
2026-01-31 16:44:11http://176.65.139.9/bins/c.shOfflinemirai ext sh ua-wget BlinkzSec
2026-01-31 16:44:11http://176.65.139.9/bins/wget.shOfflinemirai ext sh ua-wget BlinkzSec
2026-01-31 16:43:25http://176.65.139.9/bb/mipsOfflineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:23http://176.65.139.9/bins/87sbhas6as.mpslOfflineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:22http://176.65.139.9/bins/arm7Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:22http://176.65.139.9/bins/87sbhas6as.arm7Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:22http://176.65.139.9/bins/87sbhas6as.m68kOfflineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:22http://176.65.139.9/bins/87sbhas6as.x86Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:22http://176.65.139.9/bins/87sbhas6as.spcOfflineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:22http://176.65.139.9/bb/arm7Offlineelf ua-wget BlinkzSec
2026-01-31 16:43:21http://176.65.139.9/bb/arm5Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:20http://176.65.139.9/bins/87sbhas6as.arm5Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:12http://176.65.139.9/bins/87sbhas6as.sh4Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:12http://176.65.139.9/bb/arm6Offlineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:12http://176.65.139.9/bb/mpslOfflineelf ua-wget BlinkzSec
2026-01-31 16:43:12http://176.65.139.9/bins/87sbhas6as.ppcOfflineelf mirai ext ua-wget BlinkzSec
2026-01-31 16:43:12http://176.65.139.9/bb/x86Offlineelf ua-wget BlinkzSec
2026-01-31 16:43:12http://176.65.139.9/bins/87sbhas6as.armOfflineelf mirai ext ua-wget BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-05-12 19:09:236496de6f3aab639a30defdaf9571912cc16217dbcfbcf0caf77520886470981celfGafgyt
2026-05-12 19:09:2252148a6136ce081a70c4888a3bb334687ca61a2ee0820760c901c306dff70cb3shGafgyt
2026-05-12 19:09:2200749f5a02f88784dda862f0765b3369e49efd6cc9977f719424e7c39c630497elfGafgyt
2026-05-12 19:08:223ae5793510a011fb8a6fac44f22557cee0b1d5c5d65f51b7aa7bf178dc7dd3b6elfGafgyt
2026-05-12 19:07:283526ab4b9b4a61adb8e8fecc11d9a15f50447042e5b8efe1e5ed57af16cd7a1felfGafgyt
2026-05-12 19:07:19a91f6fb11ba97942349399c650644deb30aa4c1fb2170fdca2268e1dc43738a7elfGafgyt
2026-05-12 19:07:197fb05537a9e270985cb79efad8605bbf83dda2a9bd26f4cc55ebce84d0d76789elfGafgyt
2026-05-12 19:07:1954c3b17589a845cebbeee2898380c72d202b4956043387b9744db36fdfd04381elfGafgyt
2026-05-12 19:07:1935013d6c539890686e65ba7d93917588976dff97be35f44b876d8733e8a06aceelfGafgyt
2026-05-12 19:07:190fc4c95268fd72f369c5dc12123c86c0de92201bfad42be3213f9b5c127c51dbelfGafgyt
2026-05-12 19:07:19b89a43ed345c5ccdddb2b8cab501b565d55b70bc56b5f3db045a6a259bf10654elfGafgyt
2026-05-12 19:07:1485c91ff7d677a256c5a69d1adb26b070945a1e686278445221229f98674fa241elfMirai
2026-05-12 19:07:1407f4e4c5d7056fd9a50fbca51754d5bf057f4af86f4cb428014b9f9aad11c1e7elfGafgyt
2026-01-31 16:45:17a9b1f9e79de3b9f3cad71dfcde8edf81db29de8a3fe2a1789558e859b3c7c34delfMirai
2026-01-31 16:44:17d60bb0e5c7e4b2cc10b480eda59bb666c272ff272454a394f6ab61e9d554b4a0sh 
2026-01-31 16:44:169552c35479fe03b1def0c7238dccbffba36dc83efc48ccf2092918f3071cc9b2sh 
2026-01-31 16:44:114adf7e437eb11c1f470db0b4e24e56c9c2d796e03f4b4701d81d3aa353abab8eelfMirai
2026-01-31 16:44:116cfd61ba1f0936cf076f3e846071019bd1ac8c41d853d8c6d83e3724e511b75dsh 
2026-01-31 16:44:116cfd61ba1f0936cf076f3e846071019bd1ac8c41d853d8c6d83e3724e511b75dsh 
2026-01-31 16:44:110b6e813d066d7b7b6583d3c5344edc28d0f074fc1d7fa5816bd053204f1a759fsh 
2026-01-31 16:44:11809b34d42da4c0b6cbd18acde982ed2a3893f37e9191e043ed52e5dec7cfd1dfshMirai
2026-01-31 16:44:1125abad54f17538f761a029c0028ee39f50b67ae913c0b0790a03750669565927shMirai
2026-01-31 16:44:111aeb9d42be3b50bf9996472ea81ce088389866c364a0dd4929766e046e5e11fcshMirai
2026-01-31 16:43:2545f4c8845e662c17e8b2020819fe2a5500ffcb12a591353ebc5a3efbdba73435elfMirai
2026-01-31 16:43:23c6e76ea7bd94127ac850f04a940417c33b48a85700674355886b40211fdc0ca4elfMirai
2026-01-31 16:43:22eb736a1abb507ca54ec04e023d6e23df952d29a2f5d7b38cad8afe8b496482d7elfMirai
2026-01-31 16:43:22eb736a1abb507ca54ec04e023d6e23df952d29a2f5d7b38cad8afe8b496482d7elfMirai
2026-01-31 16:43:225489d9efb6ff460c835ecff7cf0e0d948fe851b6f37bc9957e2b659be553a534elfMirai
2026-01-31 16:43:2217cda7b9073c8d6dbf1d518d810a5b5bf67ee2f1b45e8b24f391b107ab6f42c1elfMirai
2026-01-31 16:43:22e95f1cf56783fbc0b64f8a670aaa34db9ea36efb87f3d607d07962b5c24af03eelfMirai
2026-01-31 16:43:2211e5f2f2ac67d22dcf08f21963078f507dae07d4fb9e3254dadb61c2618a4398elf 
2026-01-31 16:43:21d65f7c36cabc35afb3fb2bed4288880e198a1c3a014eb5ca3b6d45ec0b6e266celfMirai
2026-01-31 16:43:20512997aa6d8f23ec8ec58e54c8c8db47095c5f8c2738c36dd54bd1e1f651825belfMirai
2026-01-31 16:43:12ecb9ad7995344c9984893d419d3cf5580970ab201da3fbee3071dd5f9dde5917elf 
2026-01-31 16:43:12e772ce7b80a5d0914cba2df2489f2d76a7116a646bc44c526dc1647b3112d7b6elfMirai
2026-01-31 16:43:1189396773d9bf3eca690892f8036e71ae0964b6427775db0e0dfd4281e4ce160celfMirai
2026-01-31 16:43:11098064dbca58ad1355f436a6c1ffb7b9f7c6fddbb576ccd4e33b093f8675e692elfMirai
2026-01-31 16:43:116b164da4f15c2409732dac404ab74f59f97c947291f65b7403572ff0283391b3elf 
2026-01-31 16:43:11288678508dcaee6e8488754d6c13360ea49e69cbe7ef6d31bd2e25a2d87e7119elfMirai