URLhaus Database

You are currently viewing the URLhaus database entry for http://144.172.91.87/download/update.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3762038
URL: http://144.172.91.87/download/update.exe
URL Status:flame Online (spreading malware for 5 days, 0 hours, 35 minutes)
Host: 144.172.91.87
Date added:2026-01-22 16:06:08 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2026-01-22 16:07:11 UTC to abuse-reports{at}cloudzy[dot]com)
Tags:c2-monitor-auto CoinMiner dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-27update.exeexe ce0d36f082b79afea9594e8f97a9a8cde69f3f38a7b474675931b0a2ea0cfd2dn/aCoinMiner
2026-01-26update.exeexe b8a9fef88b09310f03ac652bff1450b9ae3a05111b9567dab8b839de07c979b9n/aCoinMiner
2026-01-25update.exeexe dd462abe81e4080bd444b29186a3c84dcef5c2c9036eb5ca5aac4c9b4bba2e03n/a CoinMiner
2026-01-24update.exeexe 8fdff18f85b2ab6e418cb72b47584de589f79606461ae0eddabaa8ff41bcca1cn/a CoinMiner
2026-01-22update.exeexe de6caea35f51991b3ac5a7e5ef82e81f05323e2ca02ed16a861701efaf96a1c6n/aCoinMiner