URLhaus Database

You are currently viewing the URLhaus database entry for http://109.248.161.103/nuts/poop which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3772266
URL: http://109.248.161.103/nuts/poop
URL Status:Offline
Host: 109.248.161.103
Date added:2026-02-05 00:17:21 UTC
Last online:2026-03-01 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2026-02-05 00:18:11 UTC to abuse{at}cloudbackbone[dot]net)
Takedown time:24 days, 2 hours, 43 minutes Bad (down since 2026-03-01 03:01:57 UTC)
Tags:CoinMiner elf geofenced ua-wget USA x86

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-28n/aelf e464d8b40e6838be2a8d4956d59d63143e898da5d1c4da98873405c5742d07e2n/a
2026-02-27n/aelf d4b79a3948c105effecc4292facee0106645f53dcb0960b6858977b5643f1290n/a
2026-02-21n/aelf 0f86ffb6a8906c26790b525ccd9480d00389c66d3fd0461d775c1cd4e9d5cfddn/a
2026-02-18n/aelf 69079a7e6e5dc7c61ae21d08b8f1886d3e418c0077bf8dfa25ec4bab9f279031n/a
2026-02-14n/aelf a3facdbc47d52be5995ae4fb2b25a21e1826c3db1a6e0b2f720d9656e54bd790n/a
2026-02-05n/aelf fe9af57a6d907d5d693355b397b00a676845ab23a778ab6485ead6a7bb802190n/a
2026-02-05n/aelf f1f57eb28380e340acececdea76a5efb3617d597225c13be9a954cb159907be0n/aCoinMiner