URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.134.201/efea6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3477321
URL: http://176.65.134.201/efea6
URL Status:Offline
Host: 176.65.134.201
Date added:2025-03-14 19:14:06 UTC
Last online:2025-04-12 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-03-14 19:15:09 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:28 days, 5 hours, 35 minutes Bad (down since 2025-04-12 00:50:41 UTC)
Tags:elf geofenced mirai link ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-11n/aelf 2b7981069924c92d27f3385d9c9196b87d212d6e81b3a9813aec9d4717679020n/aMirai
2025-04-02n/aelf 0d49952f76ba068b3ff00a848edd1ef0580c52dab241359d79b2dcab517d3b34n/aMirai
2025-03-30n/aelf 4544599d7f3d9e4c2bb3ecc5ef071f4126457ceb93fae6af5484d11d0c888a27Virustotal results 25.40%Mirai
2025-03-27n/aelf 9ee8890752bdb16935d0cc7e392d79ab9ae03ff2da2b7ca8eac9ee1d9d8f2704n/aMirai
2025-03-26n/aelf 95ba728fbf12935776ec318f88b0284d1277f6810ef6fd9c242bd7805f171df8n/aMirai
2025-03-26n/aelf 90f680d86eec3e6b865f23fe4332d4278c0158ae8b6b8af418b50e159e611310n/aMirai
2025-03-23n/aelf 596166c25a105d48e23ed949ab3e7023cc006a1a7774908520af05351c5ff607Virustotal results 25.40%Mirai
2025-03-20n/aelf d4c116ba08bacbe22b0ace4c0b5a276a58cfaf821affe69ad6b53f0a93a4c271Virustotal results 22.45%Mirai
2025-03-14n/aelf 9cfdf2330347c0989508d291fc3a0350951ced2d5525bf509f1dc99c1cf55e1an/aMirai