URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.134.30/arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3826238
URL: http://176.65.134.30/arm
URL Status:flame Online (spreading malware for 8 days, 11 hours, 53 minutes)
Host: 176.65.134.30
Date added:2026-04-19 23:39:25 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-04-19 23:40:23 UTC to abuse{at}pfcloud[dot]io)
Tags:DemonBot elf gafgyt link mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-23n/aelf 55da84bd24bef465f5db0b81f3d1d1fc202c65de4bae97b207218a992185c88an/aMirai
2026-04-21n/aelf 51909b551ba69dec9235fb6617dd94bd8669fad20402c4a662c3f821ffce649fn/aMirai
2026-04-20n/aelf d3ef47a9122cb416a78ac38c17bd19aafd292a869f3046326fb42fd3230487a8n/aGafgyt
2026-04-20n/aelf 8745bf04defd3055449c1f8ede1267a669b62aa814d5b0074ecf23f997cb88dfn/aMirai
2026-04-19n/aelf 0d757978802c6877b9f302dbcb734cf6c440aef5926a6085a145e114ee98cf63n/aDemonBot