URLhaus Database

You are currently viewing the URLhaus database entry for http://6sz.ru/ee/armv4eb which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3391515
URL: http://6sz.ru/ee/armv4eb
URL Status:Offline
Host: 6sz.ru
Date added:2025-01-06 12:56:09 UTC
Last online:2025-02-27 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-02-26 11:27:05 UTC to abuse{at}proton66[dot]ru)
Takedown time:1 month, 26 days, 3 hours, 53 minutes Bad (down since 2025-03-03 16:50:35 UTC)
Tags:botnetdomain elf gafgyt link mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-17n/aelf 2f8911081fac2c795de75fe06ddbb0fffe8c008b4988ce54dab458271380ed33n/aMirai
2025-01-23n/aelf 3ce0c728d6baf08350daae05de4cadca975c22b1b554db4cd8f47459a0cfc83bVirustotal results 14.29%Mirai
2025-01-22n/aelf 2278aaa7976942af0331f54001cc374d88da51dc3be11e035377d2729dfb0c34Virustotal results 14.29%Mirai
2025-01-17n/aelf d0564f8d5d58d66e872080911be3af2ee015f4b7f2c8a49a5dbf35011deb4736n/aMirai
2025-01-10n/aelf 08e1c67d7ff174f7ebcb7c16ae27713710a63efddeea45fd835c0033b6e799c5Virustotal results 14.52%Mirai
2025-01-06n/aelf 875a7f7214dbd9f49f84780451877ece9d61ae040726746ad51751c588d89ff5Virustotal results 30.16%Mirai