URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.139.11/bot.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3829068
URL: http://176.65.139.11/bot.arm
URL Status:Offline
Host: 176.65.139.11
Date added:2026-04-22 21:36:18 UTC
Last online:2026-04-25 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-04-22 21:37:12 UTC to abuse{at}stormindustries[dot]llc)
Takedown time:3 days, 1 hours, 31 minutes Bad (down since 2026-04-25 23:08:23 UTC)
Tags:arm elf mirai link opendir ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-25bot.armelf 8f090222817a44fa0e854382a358b5d44c75b215f5c652efa84d9e72e89d87fan/aMirai
2026-04-25bot.armelf 08ecc09a46d148fa47ad446f18c83de712f48a7ac5902fa3e3fcb81646f5109en/aMirai
2026-04-24bot.armelf ee08f1ef63f656534dd90926390b81d267a324f6a93edd265883e6af70c386cbn/aMirai
2026-04-22bot.armelf 35dd753fb9a0b4e2a3c688974f08de8e714aedd7c47aad381caffc058850a3bbn/aMirai