URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/7453936223/RenT7Wg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3607420
URL: http://178.16.55.189/files/7453936223/RenT7Wg.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-08-20 16:38:12 UTC
Last online:2025-09-25 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-08-20 16:39:14 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)
Takedown time:1 month, 5 days, 7 hours, 38 minutes Bad (down since 2025-09-25 00:17:34 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-24RenT7Wg.exeexe dbab3fbea6138e57e996045a93a3105d86e5e659bbc311d71a4e7bcc698dc353Virustotal results 43.94% Vidar
2025-09-01RenT7Wg.exeexe ab6d7532424d66be8fd4f644fc8c83c1ed2882e614f080d4051e247c06719512Virustotal results 48.61%LummaStealer
2025-08-29RenT7Wg.exeexe 1349f28cf1faba72027e7895f65998fefc49f292d827d9eb892c8b698bf91fe5Virustotal results 40.28% 
2025-08-20RenT7Wg.exeexe 2371b0a66328458ddff16721811d686dff6e689139a21ef76bd67e2b7e291e25Virustotal results 56.94%LummaStealer