URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.140.135/drea4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3430686
URL: http://176.65.140.135/drea4
URL Status:Offline
Host: 176.65.140.135
Date added:2025-02-07 06:41:06 UTC
Last online:2025-03-12 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-02-07 06:42:07 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:1 month, 3 days, 2 hours, 53 minutes Bad (down since 2025-03-12 09:36:06 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-07n/aelf b7a8882a502098f8b51aa06b9c215be250307c4e355f6f7073819d2562f23741n/aMirai
2025-03-05n/aelf a2a3d78a4c853464c0bdc960bbe43de7dbdbd3fb2209213c1be15770f35adf70n/aMirai
2025-03-05n/aelf ad13f6502225e7d33e78597a193ce30e7c7d4de585704a65f7b26eb31f83becfn/aMirai
2025-03-04n/aelf 1d0d946d1fda26a92065fa5ab288035a5d48b561ab2ed1eec916787d98c16708n/aMirai
2025-02-15n/aelf 5201ac57c50ec82c5a86ebba02483015d9cb249456c94db7c5bab63d9d50c80cn/aMirai
2025-02-07n/aelf f0baff81c648dbcb10c758da8a2236bca1665637c639de713e773730b66ed78fVirustotal results 30.16%Mirai