URLhaus Database

You are currently viewing the URLhaus database entry for http://168.138.162.78/output/client/update.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3243079
URL: http://168.138.162.78/output/client/update.exe
URL Status:Offline
Host: 168.138.162.78
Date added:2024-10-19 16:17:14 UTC
Last online:2025-05-15 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-19 16:18:11 UTC to abuse{at}oracleemaildelivery[dot]com,domain-contact_ww_grp{at}oracle[dot]com,network-contact_ww_grp{at}oracle[dot]com)
Takedown time:6 months, 27 days, 19 hours, 24 minutes Bad (down since 2025-05-15 11:42:12 UTC)
Tags:exe update.exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-02update.exeexe 7f3917d8caeef277544b3aa744a80e37e6868cd71fd76a34efb9ce33312cbeabn/a 
2025-01-27n/aexe 551d9b835909237a1e52bc5b3093fddd13b300a30d9110883bb832c677560502n/a 
2025-01-05n/aexe 7ad1133de541db9477644879dd03c5238a3e5fb403be5b09efa068d80715d76an/a 
2024-11-25n/aexe 9d4e17951922028099c60eb6f4b3694094712134d7018d32842d2d4d28a79f03Virustotal results 38.89% 
2024-10-26n/aexe c6b56d104ad74e587a58acc64b68b603d1786d07c3054d82ca29d6820f215f16n/a 
2024-10-19n/aexe 9bfe94178387ca65b1a5a65701a5b4a2edb109248bf3030cb3f75c6512e21f18Virustotal results 63.01%