URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.120.56/crypt/blessed.ps1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3418686
URL: http://87.120.120.56/crypt/blessed.ps1
URL Status:Offline
Host: 87.120.120.56
Date added:2025-01-29 15:36:06 UTC
Last online:2025-02-13 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-01-29 15:37:12 UTC to abuse{at}zhongguancun[dot]asia)
Takedown time:14 days, 20 hours, 22 minutes Bad (down since 2025-02-13 11:59:37 UTC)
Tags:encoded_base64_exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-06n/aps1 8cafc7a554a8986293b7e8db97c8b984753f7906ab4b90747ee187b9ddcaf873n/a Formbook
2025-02-05n/aps1 6e77bf3c57dd9083590de403d1b77eebcaf1f5f122fae82aaea96dced33f342bn/a 
2025-02-04n/aps1 2756326486f1e5040e843bdbdc0997c2ec112868d6658fb6f91133f6c5a8a2dbn/a 
2025-02-03n/aps1 d1a0306a5449020d8150e565d979ed765b24968f5ace1de8ac8296e7ce53eedfn/a 
2025-01-31n/aps1 af5a3eadf9beb6c219b26a2b07c0d690736e9b04afc857bff3dd930f52b3a97dn/a 
2025-01-30n/aps1 9a815a1a9b543193df99c1dbe141520d7f85fce96016c40490eedfc7c13b15f4n/aFormbook
2025-01-29n/aps1 a375d77e1af8de7846f5f8b58cd467a9c6ec2a72c45ede19d52dc3c6ed97ad6an/a