URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.53.7/cvdfnaFJBmC1/Plugins/cred64.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3614685
URL: http://178.16.53.7/cvdfnaFJBmC1/Plugins/cred64.dll
URL Status:flame Online (spreading malware for 2 months, 20 days, 16 hours, 41 minutes)
Host: 178.16.53.7
Date added:2025-08-31 11:45:11 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-31 11:46:12 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)
Tags:Amadey ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-27cred64.dlldll b67b83f78ebcc7db4a94ec331ab4daee3bf9f46cc8116c62f15f087c07685d35n/a Amadey
2025-10-14cred64.dlldll 0db8ad8a3ae44b87d9a9f39267edb6ec6fa8f23a26936ce585f123175abb70f6Virustotal results 54.17% Amadey
2025-08-31cred64.dlldll 7f8113026f9365964132e98dde901dbbf294caba44a20992a9a1e734c990ac06Virustotal results 51.39%Amadey