URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.140.135/efefa7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3430683
URL: http://176.65.140.135/efefa7
URL Status:Offline
Host: 176.65.140.135
Date added:2025-02-07 06:41:06 UTC
Last online:2025-03-12 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-07 06:42:07 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:1 month, 3 days, 2 hours, 29 minutes Bad (down since 2025-03-12 09:12:03 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-07n/aelf b15eca8497ee7c754ae99626c1b50afc2777afb0178f4b052aa7c75136c28c20n/aMirai
2025-03-05n/aelf 242ba4aeddc7525d4b76d69131faf97bfb75cccaccfcef964857feb3f5556664n/aMirai
2025-03-05n/aelf 0b2392ad25a39abf0eec115c3f923cdb4619f852849dbd7cef9c23238ed40a11n/aMirai
2025-03-05n/aelf c1d77430ce40432bdc186cc387ae129854e39450182045f9617820214e418ccan/aMirai
2025-03-05n/aelf 035a14674a66d479dc97f27791a85a0f9d02f046069343ebb3d00c0785c721fen/aMirai
2025-03-04n/aelf 62e12e674a035caf020f6d2654ce7db19937d315828af1f7253f1e3497f78f32n/aMirai
2025-02-27n/aelf 1d2abbf4e9134d0976bb6b33e86cf20fbf9b88913b1e62d463d67bc39d4ab09bn/aMirai
2025-02-07n/aelf d5e7b12a71d1e7cdb5f9b5e6b18325fd6389584680903f11607cf4aca59057caVirustotal results 65.57%Mirai