URLhaus Database

You are currently viewing the URLhaus database entry for https://220.244.1.48:8443/sda1/AV.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3612704
URL: https://220.244.1.48:8443/sda1/AV.scr
URL Status:Offline
Host: 220.244.1.48
Date added:2025-08-27 17:14:32 UTC
Last online:2025-09-14 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-27 17:15:26 UTC to hostmaster{at}tpgtelecom[dot]com[dot]au)
Takedown time:17 days, 9 hours, 43 minutes Bad (down since 2025-09-14 02:58:59 UTC)
Tags:CoinMiner ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-13AV.screxe 6867ee0924535497244a2bc712209330bec6925c46b35e7ec1a48999dad59dd3n/a CoinMiner
2025-09-13AV.screxe 840fc58cfc64674005d8fc980d3444eedff84cdd9f9240cf880c3018d6100506n/a CoinMiner
2025-09-10AV.screxe edd4eedebe03214ec8d6e22b5c5adb831bd0c6332d50a1b0246358ffd57673b1n/a CoinMiner
2025-09-08AV.screxe 182cb7fb6b85f1f34951fc8a3b7587b2fcb77e00ca37ce10dc275071e3b90f99n/a CoinMiner
2025-08-27AV.screxe efdf8e6d182ba4644375fa7eaad615b0df41f4e872e1550466e76c8b2d816ddbVirustotal results 12.70%CoinMiner