URLhaus Database

You are currently viewing the URLhaus database entry for http://6sz.ru/ee/armv6l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3391509
URL: http://6sz.ru/ee/armv6l
URL Status:Offline
Host: 6sz.ru
Date added:2025-01-06 12:55:16 UTC
Last online:2025-02-27 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-02-26 09:44:05 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 26 days, 4 hours, 22 minutes Bad (down since 2025-03-03 17:18:42 UTC)
Tags:botnetdomain elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-17n/aelf 388c12a30dcf683884280955a90a7732849a4fc28b1b1fb051d53d530edcbdf9n/aMirai
2025-01-23n/aelf 0b81de512aa6eab2e5a45c3f8577cc5d3924232a3bcbdeb77eb27e7e4e21fd25Virustotal results 17.46%Mirai
2025-01-22n/aelf 79332b029b51fd1b96af0c94e75e31eded21d4d1fa5d78268dc41f5932b8173eVirustotal results 17.46%Mirai
2025-01-18n/aelf 142480a7fe36b9df493c499d2990c4cfd327df0968a5f76a032b7d11ab823e14Virustotal results 22.58%Mirai
2025-01-10n/aelf cdc433163adee648c15f48253198ecaf211cf7d51958075f3c967b5e86c666c2Virustotal results 17.46%Mirai
2025-01-06n/aelf 1ff8b15ba325fb3f1321eca9efc451c5eaf2933cb06433d047ae526606aee707Virustotal results 29.31%Mirai