🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.134.121:8080/bot.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3918808
URL: http://176.65.134.121:8080/bot.arm
URL Status:flame Online (spreading malware for 1 day, 10 hours, 45 minutes)
Host: 176.65.134.121
Date added:2026-09-19 05:54:14 UTC
Threat:Malware download Malware download
Reporter: von
Abuse complaint sent (?): Yes (2026-09-19 05:55:22 UTC to abuse{at}pfcloud[dot]io)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-20bot.armelf 97c9c67fd7bde39b4076b26dae32b3b6bb1e91c6214d36e4de2f2d1c30087045n/aMirai
2026-09-20bot.armelf 9b8f8579deddf85f3785fd740fb3f528fc480572129ceea6dad03a371440f775n/aMirai
2026-09-19bot.armelf 5dfb9bdf78e241602d20766dbbbe65ec19a8dba654699f6f573cb7cdcbfeb86an/aMirai
2026-09-19bot.armelf 2687fe5eb866c52e73842ffa825db65da9d3feba8fbf80f6e729253c8a8ec64en/aMirai
2026-09-19bot.armelf deab8ed368ce3426027bbaef2e05cda7906a9a7ad4a72fe549a73f527e8342d8n/aMirai