URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 176.65.148.194
Firstseen:2025-06-11 04:14:03 UTC
Total malware sites :32
Online malware sites :0 (0%)
Offline Malware sites :32 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-06-11 04:14:09 176.65.148.194hosted-by.pfcloud.ioSBL679274AS51396 PFCLOUD- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-07-29 18:10:11http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:10:06http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:14http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:10http://176.65.148.194/1.shOfflinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-07-29 18:09:09http://176.65.148.194/0010101010100101101010111...Offlinemirai ext opendir DaveLikesMalwre
2025-06-13 18:46:35http://176.65.148.194/selfrep.shOfflinesh ua-wget NDA0E
2025-06-13 18:45:34http://176.65.148.194/ppc4fpOfflineelf ua-wget NDA0E
2025-06-11 21:11:10http://176.65.148.194/dvr.shOfflinecensys gafgyt ext sh ua-wget NDA0E
2025-06-11 21:09:09http://176.65.148.194/powerpcOfflinecensys elf gafgyt ext ua-wget NDA0E
2025-06-11 04:14:11http://176.65.148.194/x86Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/mipselOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/mipsOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/x86_64Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/sh4Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/m68kOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/spcOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/arm6Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/i686Offlineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/armOfflineelf gafgyt ext ua-wget ClearlyNotB
2025-06-11 04:14:11http://176.65.148.194/arm5Offlineelf gafgyt ext mirai ext ua-wget ClearlyNotB
2025-06-11 04:14:09http://176.65.148.194/arm7Offlineelf gafgyt ext ua-wget ClearlyNotB

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-07-29 18:10:117e96667d031be19d1532d524678f0239b338a1bbfc2e995b67e423fd112e1dc5elfMirai
2025-07-29 18:10:061bddecb58c4b1ef9e101d9d98f0c3a03a39ea068af1e5e4299a5f0c4b1fa8a88elfMirai
2025-07-29 18:09:143bfaf324fd7b23b789435661488a0e7f8d677d3713d2c7be3c2a412d1c498c71elfMirai
2025-07-29 18:09:108517d2bee75166456f9ca6ffec940af183937471ccbb82f6cfc71194fa287f4ash 
2025-07-29 18:09:09e780359eda5148ff97035e67609b1b23ce9438e1a64e0ff13e1c11c19efcf376elfMirai
2025-07-29 18:09:098f82296ea161e73a0bd13fb9898e3504c8fe0a9f0da0a42b583cb795eb608293elfMirai
2025-07-29 18:09:09d5afae76deeca3c7fd5b61ea2625292e8cd40da5a27e8f56e2e4f48a9cc30010elfMirai
2025-07-29 18:09:097839d44fe1d07b72e050d3872f0854018faf984c64559d2953704643e321750felfMirai
2025-07-29 18:09:093aca001c37f66284b2b02f77475997aba118a232a15eb40b8b56fa6fd3835a0eelfMirai
2025-07-29 18:09:09dd7c3bbef3aa989d5174ddbfe089ab7825336b898921c47e2384a0f01fa6181eelfMirai
2025-07-29 18:09:099457321f471cb82f0862c85c90c0773522a679a29bc344a3d462d2447a47abb7elfMirai
2025-07-29 18:09:09bd875a3e759ca935566213e2a833d160b0df2fd3a0732b5cd555c76356db0735elfMirai
2025-07-29 18:09:093a7e5e871ef067f319375b0ff6ee000abb80072ceeea9538f421a3c0c4c44e36elfMirai
2025-07-29 18:09:094603abb327738ff16e0b627352bf907b7a21198e4f7c70d20d8f0564baa420abelfMirai
2025-07-29 18:09:09bdceb942c7d54e4235920d08d60a97bfd476e3546112f1eec6deb43211353fffelfMirai
2025-07-29 18:09:093729c4397cf08612bf15dc0f158c07c145044475f142ff6c110c899bf84115faelfMirai
2025-06-12 19:35:29799c50cf8ac75ad8d837022d930f6134cfe889b6dd79da0679e1f42250ac0627elfMirai
2025-06-11 21:11:1092c7eaa5dfc642b157d74b869fca719dd72e8f0191b1d9ba2704b625688ce908shGafgyt
2025-06-11 21:09:094f2cbb52242909019bef43b0179728a39ff579f29aade60b6fb9f5843bb3f94delfGafgyt
2025-06-11 15:36:53f2463e46daafd068a312aa241baa4622a0cb2bdd6ed45ef1ef645f76dc5042e4elfGafgyt
2025-06-11 15:34:46230585b224c070247f37ce6c1b0aa3405a4b4f79ca750bd1f309f1d06090869delfGafgyt
2025-06-11 15:34:2636692e31cbb89413835b7132bd963a63cb36c541ba8db5cc4b8350b9473713bbelfGafgyt
2025-06-11 15:33:0884cf0ed553e21c39d0a8345e2eec29002b489df76f876ea5842be198c531e112elfGafgyt
2025-06-11 15:32:42e4be7d6c5c1d15011342508e5705f72de5c8772c2ebff218c02cf3ec79f29311elfGafgyt
2025-06-11 15:30:39d810aee1172b7189eb472fade4c7d24968a30bd7938013e4dab24a6827c2593aelfGafgyt
2025-06-11 15:29:305f981f7299bc39cfbaf450a6a901e39ada313b106f1d7fed9e01bd41c72a4738elfGafgyt
2025-06-11 15:27:35ad72da442c717ff4d673c498b9a59ba1068eaaab35d787400b36b6a933d47dd3elfGafgyt
2025-06-11 15:21:412d5abf4eb00cc6440b511b260e2db161218f6b40c5ee55e5ddb1b17b7154fcbeelfGafgyt
2025-06-11 15:10:00cc39e46e983daadb8c04c96be533cea97ef79966567ec625dead6c74bfd35ab5elfGafgyt
2025-06-11 15:09:590b143f828aff7469a235aabc874ad0b27d09c131aa72d924a2edc738194943c9elfGafgyt
2025-06-11 15:07:091264a8832da9e1c025dacbea5b61b98c10ae6b19e579b82382469cf57a9a27bcelfGafgyt
2025-06-11 09:39:318af3eae553f67c95b57661eaf35e8f6c3da35739afafc7d9ef0fc580cbef4b44elfGafgyt
2025-06-11 04:14:11a04b49d9fc2906911a31d688d56c3c09598a919500abf58a5fa52b6944c822f6elfGafgyt
2025-06-11 04:14:1151eb27d29770557861808d04828ea53794342051ff2b3c1a47d1bb40997f2712elfGafgyt
2025-06-11 04:14:112aaa0e9381e4cb82aea2b8fc6c5d09db77ec7a43e980ff42ce5cea01bfa6b053elfGafgyt
2025-06-11 04:14:11ad2ef2e78f40cf5159f79fc608a4f8c5db751db4f982e39c0980a40cebbb3fa4elfGafgyt
2025-06-11 04:14:11a737400844bc2929c8518cf566bc93aca44c11b2d7bb4c34fcfb6bebc2d9a6ecelfGafgyt
2025-06-11 04:14:111906d70bfe605a9d2ee52cbbd6cca36422aa2ca375162122feab0b116043b78aelfGafgyt
2025-06-11 04:14:11afb0641b156c8f45751f7b0c5624702cdbcf6f90a3ae9bcdb9cecbe295b43634elfGafgyt
2025-06-11 04:14:11e88b8653feb8bf2bc16f24afae9ddc5c58ad089844b18eda0002f1ed4cbb02daelfGafgyt
2025-06-11 04:14:1199ed85c7fcffa2e1ddbb1b2a49527f11edc5ff959cbeedb2bade01808443f19felfGafgyt
2025-06-11 04:14:11a580e2e811d2408084731d9da306e3fe2994143c5f79442c8084f4277a3497dfelfGafgyt
2025-06-11 04:14:10e8f1aa847dac41d3b10d9f4c87158f77a9097533872367a3988cde205ced5652elfGafgyt