URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.65.148.153
Firstseen:2025-10-20 03:01:04 UTC
Total malware sites :20
Online malware sites :0 (0%)
Offline Malware sites :20 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-10-20 03:01:07 176.65.148.153hosted-by.pfcloud.ioSBL679274AS51396 PFCLOUD- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-12 23:55:10http://176.65.148.153/frost.armv7Offlineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-11-12 23:55:10http://176.65.148.153/frost.x86Offlineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-11-12 23:55:10http://176.65.148.153/frost.armv5Offlineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-11-12 23:55:10http://176.65.148.153/frost.mipsOfflineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-11-12 23:55:10http://176.65.148.153/frost.x86_64Offlineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-11-12 23:55:09http://176.65.148.153/frost.armv6Offlineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-11-12 23:54:06http://176.65.148.153/dvr.jaws.shOfflinegeofenced Ngioweb sh ua-wget USA botnetkiller
2025-11-12 23:54:06http://176.65.148.153/frost.mipselOfflineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-11-12 23:54:06http://176.65.148.153/frost.aarch64Offlineelf geofenced Ngioweb ua-wget USA botnetkiller
2025-10-20 03:01:09http://176.65.148.153/x86Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:09http://176.65.148.153/coOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:08http://176.65.148.153/586Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:08http://176.65.148.153/dssOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:08http://176.65.148.153/i686Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:08http://176.65.148.153/sh4Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:08http://176.65.148.153/arm61Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:07http://176.65.148.153/mipselOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:07http://176.65.148.153/mipsOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:07http://176.65.148.153/m68kOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-10-20 03:01:07http://176.65.148.153/ppcOfflineelf gafgyt ext ua-wget ClearlyNotB

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-13 05:32:36a155191721c632cf9380947e3a29c27b5146f8c5590d517d52262e36753a0875shNgioweb
2025-11-12 23:55:105bd31c712bc667714d6abf1823c3abd23c909831aa83e5597d9e4c8a280da029elfNgioweb
2025-11-12 23:55:103ac2952c0a1f755baa86d7acbac01a08be67beec8cf286a5f59fc9ca2f4e0231elfNgioweb
2025-11-12 23:55:100ca4e6fd9ab8da9824cc1ef5dd30d5635f505b15f115b12aaf1fad3cc946c5aaelfNgioweb
2025-11-12 23:55:107e7b6974e650aa30dbc3e3c399ea9f2aeba9c3ede0fa65b4ca12589b95dd8912elfNgioweb
2025-11-12 23:55:10e4a963b5164ee3baa9afd4ef69c469fa640816742bc232c9c5cbc47f42f2e352elfNgioweb
2025-11-12 23:55:0984f4fd11e3eb8e4202daebe02e1e45f132a8081df97d6ec853fcebe8d1b47c5felfNgioweb
2025-11-12 23:54:06b01cd96e5f4399a616968ee1b551c58ba914d238531ce570f99491c2e5e7963eshNgioweb
2025-11-12 23:54:06b748778a3d29f9927144d643783933a5a72775cf125b27924bcad4ada27a6269elfNgioweb
2025-11-12 23:54:066e506f968ff88fb4eddbc0b99d3c24627b5b8d64a4d8f72e6003586e40f6b37belfNgioweb
2025-10-20 03:01:09962c7912c44af279cd7879402913ca17968a64788b041b855867d42bf0441387elfGafgyt
2025-10-20 03:01:08cf9a897fadec97206fe1f75f6978a04c333d37ac418fc1525bcabe3f13f225a0elfGafgyt
2025-10-20 03:01:08a33aa07b8f51e7bfee450b08b563fb72d93834f9955ad189795a49532f3cce97elfGafgyt
2025-10-20 03:01:08729fdb587dd9b93b8d689209d68b2ef32678cb3263177d79e443046fb278c93celfGafgyt
2025-10-20 03:01:085bb6b335d5df8e953dafe382ef810d5629fa15f959655c1fcbe2af815ad4bb13elfGafgyt
2025-10-20 03:01:08e6e0d5334a6b305ecb60f563aa16cb5d47ffa420a03799c030ac51d3ab869ff3elfGafgyt
2025-10-20 03:01:08e4393a49350ed5e410e1cf286c4b8b6df29224348c9972aadcded5cb74874fbaelfGafgyt
2025-10-20 03:01:07c1083f406437651d99f4b0a6fdbb3dc57f7268fc3c1f071b8330007ca9f36de6elfGafgyt
2025-10-20 03:01:07684668d3065daad253570100f3b947a50aad9be3e4429d02c156176899e23e60elfGafgyt
2025-10-20 03:01:07995e632e29a9c2635cfc9f693950e3ad07ae18028968e1427b306bb72e573a00elfGafgyt
2025-10-20 03:01:06bcc239c8ac93b5b198fd4c5be8da9a252ef9149fcc3c13986d364826a9c8d900elfGafgyt