🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.139.234/main_x86_64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3916574
URL: http://176.65.139.234/main_x86_64
URL Status:flame Online (spreading malware for 6 days, 12 hours, 2 minutes)
Host: 176.65.139.234
Date added:2026-09-15 00:03:19 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-09-16 16:21:18 UTC to abuse{at}stormindustries[dot]llc)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-19n/aelf bef2d6cf3c1514d5b7b8afe65c0da256d58cd6c580602fadbdd4d097b0a10453n/aMirai
2026-09-19n/aelf 25c88a84f1442edbdf641c902534b4793bee3533c5ec499a342d0ed768c6f601n/aMirai
2026-09-18n/aelf 125c7ffc9bb233e96bfb34c2de3140652bbe110ac08bf35b1316b65281d49781n/aMirai
2026-09-18n/aelf 1492db8f5645b277862ee39ff766a7d479ae19228a02c6448fd3f45f2fe63cc9n/aMirai
2026-09-17n/aelf aca1af342bedb8c62089e47c36ed3ddf55d3c7949edef6ee40ccd6fae21c0907n/aMirai
2026-09-16n/aelf b926a736d742878537ff6a9681b1070cc3cc055774752f959b4112bc1afe6d27n/aMirai
2026-09-16n/aelf a1f7f1c9e23a3b886d08e36299f193ae606187c93a67bcc82cf36389a66a2df1n/aMirai