🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.134.121:8080/qzxuuppn.aarch64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3920610
URL: http://176.65.134.121:8080/qzxuuppn.aarch64
URL Status:flame Online (spreading malware for 2 days, 17 hours, 59 minutes)
Host: 176.65.134.121
Date added:2026-09-22 05:16:28 UTC
Threat:Malware download Malware download
Reporter: von
Abuse complaint sent (?): Yes (2026-09-22 05:17:24 UTC to abuse{at}pfcloud[dot]io)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-24n/aelf f1580e682cfaf7fba54e19df322ebb4c1647039a56c3dc7769d559e8e6709ce5n/aMirai
2026-09-24n/aelf f6b4b65b886a6f9721eb609a15dc1327b747e1ef902e542981bcb9b180dd510fn/aMirai
2026-09-24n/aelf 06f60decb67aca3b77cafa5387642316926a60c0a37da78f1004a4581dd484a9n/aMirai
2026-09-23n/aelf 63fe07ba950defe03bdba7d5cbd35d17243f0315bd514a3dbb77cb0e717e50d0n/aMirai
2026-09-23n/aelf 28997754d3e854fb85ac7c067453207af96c2afca820f4f7bf9ec035ba0f0093n/aMirai
2026-09-23n/aelf b8d4248c4741edf839d943a5ce1824040eff39c89cb5c025cda56edd833570a9n/aMirai
2026-09-23n/aelf 4935ae2958fbd512f7ecdb323c4fa20c77a6ea14b044c4bb423b9a0d36de5f72n/aMirai
2026-09-23n/aelf 90a7cd85a4510a5e91b4aa521fe676e349ff4ae87625654f1479902dcb8dfd82n/aMirai
2026-09-22n/aelf 59227b4417d38cdb1c216ef0c911bbefaafdc982ea0b2a318199b45fea135139n/aMirai
2026-09-22n/aelf b145b5bb3cf0182180e926335f6cf62f00b0524a4d0bf0158ea6136d34d5fe89n/aMirai