🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.134.121:8080/qzxuuppn.armv7l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3920743
URL: http://176.65.134.121:8080/qzxuuppn.armv7l
URL Status:flame Online (spreading malware for 2 days, 8 hours, 23 minutes)
Host: 176.65.134.121
Date added:2026-09-22 05:17:10 UTC
Threat:Malware download Malware download
Reporter: von
Abuse complaint sent (?): Yes (2026-09-22 05:18:26 UTC to abuse{at}pfcloud[dot]io)
Tags:mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-09-24n/aelf 47277cc7c5e0f0381ac9a6051b0a0647888a34b08f9553e4d31486a4e3578116n/aMirai
2026-09-24n/aelf 70690631540ec12da870d1820f7cecbaa09b2f33ae5273bd8fdff32713137c40n/a
2026-09-23n/aelf c0dc95c796d4c73deaa55bda0ab80173e4748516dda4a81a19d57ec9ab7c5fbbn/aMirai
2026-09-23n/aelf de7a856cf18de623c98a39a6f603366d1ef01e087b60005b43909c411fcb6cdcn/aMirai
2026-09-23n/aelf e9eba29758bac1901b3fcd682ee8541092658510da8641f44fc8142729c33641n/aMirai
2026-09-23n/aelf 636b7015999de5baa5d9d73de875f20a291df6ceb94e39ede69d20bfc74c24aan/aMirai
2026-09-23n/aelf 732e14f0a44613fbfd90cd4958a1d2171970b52adf283416f044fbea4957c460n/aMirai
2026-09-22n/aelf 174ee3aed523f1f415e2dd7f5d5ecce743c4195cec895ffc126fad8d8f569085n/aMirai
2026-09-22n/aelf aaf45dcc5c1fa53c3f9fb482e9d5ac941b5ea30740779358726100b8ae9d44bfn/aMirai