URLhaus Database

You are currently viewing the URLhaus database entry for http://104.194.152.180/download/update.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3765377
URL: http://104.194.152.180/download/update.exe
URL Status:Offline
Host: 104.194.152.180
Date added:2026-01-29 02:33:08 UTC
Last online:2026-02-21 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-01-29 02:34:11 UTC to abuse-reports{at}cloudzy[dot]com)
Takedown time:23 days, 11 hours, 5 minutes Bad (down since 2026-02-21 13:40:01 UTC)
Tags:CoinMiner dropped-by-amadey fbf543

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-12update.exeexe 68c7feb45d7becc15a381cc197459aa67596e3eae369f3eaac0410673c959c11n/a CoinMiner
2026-02-11update.exeexe 6fa3a3e4f274de7bce6485c28e7b89ff9df902a15c53f67df2e6a9188e6427a4n/a CoinMiner
2026-02-10update.exeexe 767c5cfa08666973e6d22d701f1314434ceb7ef1ca24d22ac10592c7af146a5cn/a CoinMiner
2026-02-09update.exeexe 079899928bd2193d728e8b8afdd7f4cce41215d187cbbd82c5dfa1588ce825abn/a CoinMiner
2026-02-07update.exeexe 17d5626a3b75948391a3bc688410e2d00a95fe0aa4da706e0d6beddefc5f2b6cn/a CoinMiner
2026-02-04update.exeexe 7e0451a0ab373b30fe2750353096f45cca60d42d5c42fdc65806c5b5b8475091n/a CoinMiner
2026-02-03update.exeexe e2897b0ff3216f76457999ea653a7974932ee76ebd30972ca4c2d93eea3c378en/a CoinMiner
2026-02-03update.exeexe 32021429efd71f380c95a761c97a974fa0e3e9f67f6ccf4f17baf6f0707ef36fn/a CoinMiner
2026-02-02update.exeexe 52c9e5c012e5318737516d7aa061f66323d91012cde7f90faa70688dc2969760n/a CoinMiner
2026-02-02update.exeexe 50b1139cf28c6dccaf8a809cf0d29805f0f04e916cd9d89f678cbed55baeb233n/a CoinMiner
2026-02-01update.exeexe e9f62319cce64087b72b10ae6df0154abbe1994cd7e0150e1b2780d9c7a07fbbn/a CoinMiner
2026-01-31update.exeexe 8091fcdae12aa7a48d230617307c9d369c973622fa491643a0efb2f212e4a29bn/a CoinMiner
2026-01-30update.exeexe a209151a1ed2f1064d0576fdc1a56e2f743409635fbbac450989f49930d65dd1n/a CoinMiner
2026-01-29update.exeexe f7271f783c49dbe7d42e2a22df2bdaec0523ac7d7ef3273fa0288c71a440b48fn/a CoinMiner
2026-01-29update.exeexe fcd89fa42d24b330d8661064a5d40660b95deff7a741663ff11e8be65cf91af1n/aCoinMiner