URLhaus Database

You are currently viewing the URLhaus database entry for http://proxy.amazonscouts.com/lopsa/66c6efd6b6f8b_123p.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3223407
URL: http://proxy.amazonscouts.com/lopsa/66c6efd6b6f8b_123p.exe
URL Status:Offline
Host: proxy.amazonscouts.com
Date added:2024-10-07 19:10:51 UTC
Last online:2024-10-22 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-07 19:11:13 UTC to karina-rashkovska{at}ukr[dot]net)
Takedown time:14 days, 21 hours, 2 minutes Bad (down since 2024-10-22 16:14:03 UTC)
Tags:CoinMiner

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-16n/aexe 9bafa495268978a21e5b584fdf9dcfe0c7c8a22a97168b63699f3299546044e4n/a 
2024-10-14n/aexe d4dd9bc80075ddf0ae911716ac9ce0d1b55eb6713a358ad605f93d460e69ffacn/a 
2024-10-11n/aexe 73b1fb8b3002e1e043dee90acfe9542c8b1c906f6f9a502e7c78a1c24abd11f4n/a 
2024-10-09n/aexe 9e947ec29bd1b88904e878618d8e8bdf3cad79dec2559b8c67dfee5fbcf77503n/a 
2024-10-09n/aexe 45d4fafc59be11f5889f6797ef7b0923cdde4c9058908642e4efcfa7b29a4acan/a 
2024-10-07n/aexe 7870d51e2ec6a82fede5bcb9a3dd55c530354b9847b1342e15bfd9f6dc5b40fbVirustotal results 77.78%CoinMiner