URLhaus Database

You are currently viewing the URLhaus database entry for http://61.163.102.174:9999/help.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2888431
URL: http://61.163.102.174:9999/help.scr
URL Status:Offline
Host: 61.163.102.174
Date added:2024-06-14 11:51:35 UTC
Last online:2024-08-13 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-06-14 11:52:09 UTC to zhaoyz3{at}chinaunicom[dot]cn)
Takedown time:2 months, 0 days, 4 hours, 30 minutes Bad (down since 2024-08-13 16:22:52 UTC)
Tags:CoinMiner help.scr TellYouThePass

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-11n/aexe e4e7973a3d788a4028eeb5fcb4f8e2b478575c941ed0a993a56d7187334004a0n/a CoinMiner
2024-07-24n/aexe 0c1f4a22aa0a61ea57e65916c2b9d1ae53948301edd8d40cd123b50a4289b9f3n/a CoinMiner
2024-06-14n/aexe 01c9940b468ce2a58f2bc52f5c8b7d0310451c994d798879ff653d92fbaf8719Virustotal results 78.08%CoinMiner
2024-06-14n/aexe 19992bca1ff8fabaa74f2ab0376977fc8059b5bf6e6daa25572ea5646e70f196n/a CoinMiner