URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.65.148.145
Firstseen:2026-08-04 18:59:05 UTC
Total malware sites :16
Online malware sites :0 (0%)
Offline Malware sites :16 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-08-04 18:59:20 176.65.148.145176.65.148.145.ptr.pfcloud.networkSBL679274AS51396 PFCLOUD- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-08-04 19:24:28http://176.65.148.145/n2/tbkOfflinesh ua-wget botnetkiller
2026-08-04 19:12:27http://176.65.148.145/n2/x86_64Offlineelf ua-wget botnetkiller
2026-08-04 19:11:13http://176.65.148.145/n2/armv7lOfflineelf mirai ext ua-wget botnetkiller
2026-08-04 19:11:13http://176.65.148.145/n2/armv5lOfflineelf ua-wget botnetkiller
2026-08-04 19:11:13http://176.65.148.145/n2/m68kOfflineelf mirai ext ua-wget botnetkiller
2026-08-04 19:11:13http://176.65.148.145/n2/sh4Offlineelf mirai ext ua-wget botnetkiller
2026-08-04 19:11:13http://176.65.148.145/n2/sparcOfflineelf mirai ext ua-wget botnetkiller
2026-08-04 19:10:27http://176.65.148.145/n2/armv6lOfflineelf mirai ext ua-wget botnetkiller
2026-08-04 19:10:27http://176.65.148.145/n2/armv4lOfflineelf ua-wget botnetkiller
2026-08-04 19:10:27http://176.65.148.145/n2/ppcOfflineelf ua-wget botnetkiller
2026-08-04 19:10:27http://176.65.148.145/n2/aarch64Offlineelf ua-wget botnetkiller
2026-08-04 19:10:27http://176.65.148.145/n2/mips64Offlineelf mirai ext ua-wget botnetkiller
2026-08-04 19:10:27http://176.65.148.145/n2/x86Offlineelf mirai ext ua-wget botnetkiller
2026-08-04 18:59:31http://176.65.148.145/n2/mpslOfflineelf mips mirai ext ua-wget botnetkiller
2026-08-04 18:59:21http://176.65.148.145/n2/mipsOfflineelf mips mirai ext ua-wget botnetkiller
2026-08-04 18:59:20http://176.65.148.145/n2/lterouterOfflinesh ua-wget botnetkiller

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-08-04 19:28:54b04dd6daaf2f6606559de3f0b45574e804110f67c69c71326967443d8584daf4sh 
2026-08-04 19:12:27850c6f47e765f8d386025b81b5efcbcd66da777b959961f310b40e3d014df34delf 
2026-08-04 19:12:0583bfe81f9d729d349eda5147a6f023081ff431d993e5a49a2f0e36a4ef7912bcsh 
2026-08-04 19:11:303cf154dfdf1790f2fd185f6f5ac618c75c0d6ff83ca19812e272da6bdb8bd4b5elfMirai
2026-08-04 19:11:13fd5a48693a99cbb7c49f5f4245f3090ffeec58ce3f9d9bcf7f6c7eade62769f1elfMirai
2026-08-04 19:11:138df261ce0672369e08e79f205a15e338b1196ebc0f15fa5692027b68d67da378elf 
2026-08-04 19:11:13f4806381ad322bf97c3a943e7659b8d8df20eee28d8919c94b0876d31b614f7aelfMirai
2026-08-04 19:11:13b33314b1f39bccb57eef08a32f7d7c9d2562fd047729aaf184fbd2b0bd3f9927elfMirai
2026-08-04 19:11:1330e712886468101512540db1315efc7d029ea897be5aa6f5b381cfdd0a3f2eb7elfMirai
2026-08-04 19:10:27fcd0c4676a7b813715aeafd9f5084c166781ea5bc9f618231285055a189e396belfMirai
2026-08-04 19:10:27d5d41bf6ec3d3bfe82546234a095654cfa4200fefec12889689ac4d609076a95elf 
2026-08-04 19:10:2729547e914112958a04fc47b20f25e91a4326f9e71d9ca4aa02f3d81e5cf12da7elf 
2026-08-04 19:10:2705a0ca0ac2527c0faddc2a8ec456e69fc1f0e0c9fff9d2d396327faf3f876c30elf 
2026-08-04 19:10:2787129c7eee65f5185ca3977ec2aab905c879765226d1f07813db3a768c5aaf33elfMirai
2026-08-04 19:10:27c8a5864552ab341135ce5d590f314ac8856c827b6af2745256590d47fb94822eelfMirai
2026-08-04 18:59:31c1879bbc63385aba9bbc4dfd6386b5a9fd66482060e38acc4f78ce4345104f58elfMirai