URLhaus Database

You are currently viewing the URLhaus database entry for http://5.26.174.234/AV.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665733
URL: http://5.26.174.234/AV.scr
URL Status:Offline
Host: 5.26.174.234
Date added:2025-10-09 05:53:30 UTC
Last online:2026-05-27 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-10-09 05:54:40 UTC to abuse{at}turkcell[dot]com[dot]tr)
Takedown time:7 months, 20 days, 13 hours, 21 minutes Bad (down since 2026-05-27 19:16:07 UTC)
Tags:CoinMiner

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-31AV.screxe b80cb197022fba62395ec769097d57edb4676618e1fa13519dc1544ddf6ac6e8n/a 
2025-11-15AV.screxe aa26cbab6dbccd7a147a8e28e4f009369e6330cf743f26edf651fe16fd984180n/a 
2025-11-13AV.screxe 93bd76b239029c405bebe2c1fe2c90de87a2eb3b4cb764366ff8995c1d70416dn/a 
2025-10-22AV.screxe 03a8b5a8deeb7b269c9c48239f5ef667728045ad9fb4f5e3d19eb4bf8adfd621n/a CoinMiner
2025-10-09AV.screxe a06567aeca3dd18ed732a26239f5fd71d43ea8978374f30d436048bec1f6e95bn/a