URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.125.72/garm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3401750
URL: http://87.120.125.72/garm6
URL Status:Offline
Host: 87.120.125.72
Date added:2025-01-15 14:47:09 UTC
Last online:2025-02-07 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-01-15 14:48:12 UTC to abuse{at}ekabi[dot]net)
Takedown time:22 days, 21 hours, 34 minutes Bad (down since 2025-02-07 12:22:52 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-27n/aelf e33a191716e1634f351fc77a287e605f0b2686d88c7cbb3773ae70e9a12e3ffcn/aMirai
2025-01-25n/aelf 829555e6fa380def3f557b97cc60551c1df898f7dc82d3cfe611044585050f31n/aMirai
2025-01-23n/aelf d73ea417a77b7e983cd9e1048406a664863c6bece82f6d3c09d278237765a510n/aMirai
2025-01-19n/aelf 8acad8d8078fb0408eda2dc962435e6d96269edf5e9aa963033e66a3c0669815Virustotal results 25.40%Mirai
2025-01-15n/aelf 2fe129193ab490709239439578830f6ff60cfccf2fe5d405e5a447a8b6629709Virustotal results 61.90%Mirai