URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.120.56/crypt/code.ps1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3418688
URL: http://87.120.120.56/crypt/code.ps1
URL Status:Offline
Host: 87.120.120.56
Date added:2025-01-29 15:36:06 UTC
Last online:2025-02-13 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-01-29 15:37:12 UTC to abuse{at}zhongguancun[dot]asia)
Takedown time:14 days, 12 hours, 49 minutes Bad (down since 2025-02-13 04:26:25 UTC)
Tags:encoded_base64_exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-07n/aps1 b54d5ffb019e7bfb25ee5b26b559ec18692ad4b58a23b9cc37f21901890dc7fan/a 
2025-02-04n/aps1 222eeb7c32e970c4d3dffefc60e9b845cb3e8e88e9f7288ecb46c746b5b0ab94n/a 
2025-02-03n/aps1 735388e79ad98df60ee4791d1ee59ad4245bf80f44fdc7fb709cfa74cd8039fan/a 
2025-01-31n/aps1 1d3ef8247696124f8665e4dc57adc09326a73b12483715d8332d0d9615f47156n/a 
2025-01-30n/aps1 47b182288c5f580e495435f773f7a8745b4bf90cd19db821dfce207eb10e3f23n/aFormbook
2025-01-29n/aps1 4dac7e5007ff2b4ce31e5ebc80d7508e84308bca9f871102e5aa098ab414d210n/a