🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.134.121:8080/bot.aarch64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3918791
URL: http://176.65.134.121:8080/bot.aarch64
URL Status:flame Online (spreading malware for 1 day, 8 hours, 38 minutes)
Host: 176.65.134.121
Date added:2026-09-19 05:53:15 UTC
Threat:Malware download Malware download
Reporter: von
Abuse complaint sent (?): Yes (2026-09-19 05:54:16 UTC to abuse{at}pfcloud[dot]io)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-20n/aelf d8ed7463bbcf3cf511d4a1a1a11c2e25010d68b9b7b85097c2d3707b172e72can/aMirai
2026-09-20n/aelf 8d0584a13d7a0619e3d33261e70c649b54ad9969780419345612862a75043bf8n/aMirai
2026-09-19n/aelf 3f9c927ffc175b312d0836b2bc98a0135497dcf984a2fefdcb35c41b20f48877n/aMirai
2026-09-19n/aelf 921a2da9d9dcdd01ad367b1ebf7e0d1a30c8876f8a855af537c08e89cffc372cn/aMirai
2026-09-19n/aelf 65ada4a3f7cfeb7201704c8ed0cc87bb391f7ea17ab223e39b23ce9d15b63ad2n/aMirai