🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.139.234/main_sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3916580
URL: http://176.65.139.234/main_sh4
URL Status:flame Online (spreading malware for 11 days, 4 hours, 32 minutes)
Host: 176.65.139.234
Date added:2026-09-15 00:03:19 UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2026-09-16 17:17:17 UTC to abuse{at}stormindustries[dot]llc)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-19n/aelf 2d3c0d6305c349e8a520a40baa6fa330478488479a8af4743e3aee5e3426c426n/aMirai
2026-09-19n/aelf 9ad719ab9e1b3878081f8f068c83f6979b9eb172b27f23119f531e9994d2da50n/aMirai
2026-09-18n/aelf cdaaddf9899b75756836a48718b71652e03b9e31b07152e59913613b749deec5n/aMirai
2026-09-18n/aelf fe2a22942033fab5625c751d20ba5284432b5820f59f7303b1ceb9977849173dn/aMirai
2026-09-17n/aelf 6de52bf640672f675ffa96d1d5edb299741d062da175033e537b423008bab116n/aMirai
2026-09-17n/aelf d33c0076eb4ef5b42bda0af2e0a01942c1438a23762ad362cb5a6d1fa82916d8n/aMirai
2026-09-16n/aelf 199e3ea8b6351cb5dc3b084113e6483fcc29157803f27476c6e37a6f4d15ecbfn/aMirai
2026-09-16n/aelf ba6ef9eb1a2e50818106c7b227df80a9fdd6819ec7a1913222d92b56f5ccbe4fn/aMirai