URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.125.72/garm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3401744
URL: http://87.120.125.72/garm7
URL Status:Offline
Host: 87.120.125.72
Date added:2025-01-15 14:47:09 UTC
Last online:2025-02-07 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-01-15 14:48:10 UTC to abuse{at}ekabi[dot]net)
Takedown time:22 days, 21 hours, 41 minutes Bad (down since 2025-02-07 12:30:03 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-04n/aelf 373fdadadb6fd49ee4da35bf1bce2774fdbe171cc3de062cb7b9bfb4d3d54412n/aMirai
2025-01-23n/aelf d8da26cc88c1959891812d6fcf196002c51249912b4b87115b240653d2a9895cn/aMirai
2025-01-19n/aelf 587da8b2bd23a6379d81265164da4f21ac1a351b7fd6d5feff006b92f20b2f90Virustotal results 30.16%Mirai
2025-01-15n/aelf 044f2d0a3268bccd9e6c38e35bda5d7d5206feb6c34ae8ad384a7655346a667eVirustotal results 63.49%Mirai