URLhaus Database

You are currently viewing the URLhaus database entry for http://87.120.120.56/crypt/pappy.ps1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3418689
URL: http://87.120.120.56/crypt/pappy.ps1
URL Status:Offline
Host: 87.120.120.56
Date added:2025-01-29 15:36:06 UTC
Last online:2025-02-13 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-01-29 15:37:12 UTC to abuse{at}zhongguancun[dot]asia)
Takedown time:14 days, 12 hours, 49 minutes Bad (down since 2025-02-13 04:26:43 UTC)
Tags:encoded_base64_exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-02-07n/aps1 556f8945f3029629a11942aff6ba409da19e914e5a3c65f28f8c154b41b926d7n/a Formbook
2025-02-06n/aps1 84d3fa9e409d2c69b29ea5779b3b7d5ae274478a2fb26eae25d64609e5b166f7n/a 
2025-02-05n/aps1 e98d8a463c4d70f515a6376115d7474cab681d1ffe646b601a34f262cad9ad01n/a 
2025-02-04n/aps1 65731f35e260f1d98142536dab05f780d2a3abd50f01b90e850f93c8dab6f1d3n/a 
2025-02-03n/aps1 44ee86ca7594da1b1af6d3f03fabd9379c2f630a816171ba80a7d377e7f61148n/a 
2025-01-29n/aps1 cbd4df99128d620e410e2698704df341cca76027487e61dbea615fde5ffb5360Virustotal results 16.67%Formbook