URLhaus Database

You are currently viewing the URLhaus database entry for http://6sz.ru/ee/armv7l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3391475
URL: http://6sz.ru/ee/armv7l
URL Status:Offline
Host: 6sz.ru
Date added:2025-01-06 12:55:15 UTC
Last online:2025-02-27 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Malware domain
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-02-26 10:57:05 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 26 days, 3 hours, 12 minutes Bad (down since 2025-03-03 16:08:36 UTC)
Tags:botnetdomain elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-17n/aelf d822048a8eb925046edc4e5e72c41d82c56093dd87bb22f49685326d85986769n/aMirai
2025-01-23n/aelf df9c88f321b95bbf16c81b29fc8a88421087c45ad0415d462bb547134ae91053n/aMirai
2025-01-22n/aelf 22461ce6d814bde20589639e61da17ad79b612eafdcdc0248277b9e41a64169en/aMirai
2025-01-17n/aelf d45266e585b60efa1bd2f702bf51a0ffbafba0b7416a58e9b3cd45efa3301c9dVirustotal results 19.05%Mirai
2025-01-09n/aelf 919626e4f6cd7808f484b7ab9b3e4fb62a6405bb152eaa7037a9aefa273665b6n/aMirai
2025-01-06n/aelf 808e7677d1412b248b1767f7e9a64834e2fae96d95d92b4cea73be189e36e291Virustotal results 15.87%Mirai