🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.134.121:8080/stub.armv6l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3920684
URL: http://176.65.134.121:8080/stub.armv6l
URL Status:flame Online (spreading malware for 2 days, 21 hours, 9 minutes)
Host: 176.65.134.121
Date added:2026-09-22 05:16:45 UTC
Threat:Malware download Malware download
Reporter: von
Abuse complaint sent (?): Yes (2026-09-22 05:17:36 UTC to abuse{at}pfcloud[dot]io)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-24n/aelf eff8a8e175ea3be6bc9c5d4725538e932c9933d20ef35de082a2a6397906e7c0n/aMirai
2026-09-24n/aelf b00989bc0e00ae4da0ca4fa0a4fe2115000ce387e7a4b4159573a820d6d602adn/aMirai
2026-09-24n/aelf e7c714c9c208e21b96aea6e18547b193fa017f9da07aee71002592f0bec22ebfn/aMirai
2026-09-24n/aelf a2e26834d907795d8239562f2dff1daa3ccf5fce307c287baca9029ad41f283an/a
2026-09-23n/aelf c8ae7e10d4d17da105c98729894f366e5f95c47c4bd97d56c07b167befd72852n/aMirai
2026-09-23n/aelf 7389de756b073fec59249ade29f15065b03668f2b580ee93ce95be1d40941a53n/aMirai
2026-09-23n/aelf aa11c57550c38f8614ff70ca734a588c1a426bb5e35cf090204be3528fb0141en/aMirai
2026-09-23n/aelf 211161fb55aa862e691e01cba1c9d359dd2727c1c12cbad2dcfa9085b56a9240n/aMirai
2026-09-22n/aelf 5492f9606bf12add8b8414b224e8272b7d422baedbd951e8874a4bda0cb716bcn/aMirai