URLhaus Database

You are currently viewing the URLhaus database entry for http://212.70.149.164/Photo.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2911010
URL: http://212.70.149.164/Photo.scr
URL Status:Offline
Host: 212.70.149.164
Date added:2024-06-28 13:54:08 UTC
Last online:2024-07-17 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-06-28 13:55:11 UTC to abuse{at}4media[dot]bg)
Takedown time:19 days, 8 hours, 32 minutes Bad (down since 2024-07-17 22:27:51 UTC)
Tags:CoinMiner exe iframe Photo.scr scr

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-11n/aexe 807126cbae47c03c99590d081b82d5761e0b9c57a92736fc8516cf41bc564a7dVirustotal results 94.59% CoinMiner
2024-07-08n/aexe d18f87c4b237ee2fe8cd55a09036a74de1234304072e0ae718b756ae8bb28e47Virustotal results 5.48%
2024-07-07n/aexe f5508a6f0a26f4dc7126d1998eb58e847ada0f0249adbe3a48194deb6c450b66n/a CoinMiner
2024-07-07n/aexe e19f3a1bfdef9fd9aac8158ae05d35fbbcca7bc2574f3fc0c789d8d04b274f55Virustotal results 11.43% 
2024-06-28n/aexe af94ddf7c35b9d9f016a5a4b232b43e071d59c6beb1560ba76df20df7b49ca4cVirustotal results 82.19% CoinMiner