URLhaus Database

You are currently viewing the URLhaus database entry for http://pic.shouhucj.com/Photo.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2911112
URL: http://pic.shouhucj.com/Photo.scr
URL Status:Offline
Host: pic.shouhucj.com
Date added:2024-06-28 14:43:30 UTC
Last online:2024-09-27 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-06-28 14:44:15 UTC to support{at}7991[dot]net)
Takedown time:3 months, 0 days, 13 hours, 33 minutes Bad (down since 2024-09-27 04:18:02 UTC)
Tags:CoinMiner exe iframe Photo.scr scr

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-08-12n/aexe 9f0b890db55054251de84cf390eaa51a19f66d86e7559042512ff6e4e460e9f0n/a 
2024-07-20n/aexe 9194b57673209c8534888f61b0cdefa34f463ae50cd78f72ab2b3348220baaf9Virustotal results 82.19% CoinMiner
2024-06-29n/aexe 617e6896100c4289af8ec35ce7b719ea50c18d006b1e4e4c5fefdbee65b6fbbdVirustotal results 1.82% CoinMiner
2024-06-28n/aexe eaf34aa272aa6550ae45d504c10f4d90b6609ec7a57bff4ba4a8e8f273e2736fVirustotal results 3.03% CoinMiner