URLhaus Database

You are currently viewing the URLhaus database entry for http://43.132.13.252:9000/Photo.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3216334
URL: http://43.132.13.252:9000/Photo.scr
URL Status:flame Online (spreading malware for 1 year, 7 month, 28 days, 17 hours, 9 minutes)
Host: 43.132.13.252
Date added:2024-10-06 12:46:49 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-10-06 12:47:44 UTC to qcloud_net_duty{at}tencent[dot]com)
Tags:CoinMiner exe iframe Photo.scr scr

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-23Photo.screxe fb7dcd9524c7275e7ddbbb9c195bb736b676e5178ad43259b60668ed563e7457n/a CoinMiner
2025-05-09Photo.screxe 595fcc540ee8fe4408c141b7c403d9b0d678456efd6f131b365a22c0498c24fdn/a CoinMiner
2025-05-08Photo.screxe 5be8b94ae708e88746720855a1413cc7d71a70c8c60a0c968233d76ee112f773n/a CoinMiner
2025-03-03n/aexe 62e4de382d1e84efe7a2a6ae9f1f7bca02a5bb18faa7f97a5ab915d1309853a3n/a 
2024-10-06n/aexe 807126cbae47c03c99590d081b82d5761e0b9c57a92736fc8516cf41bc564a7dVirustotal results 95.83% CoinMiner