URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/unique4/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3614701
URL: http://178.16.55.189/files/unique4/random.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-08-31 12:29:08 UTC
Last online:2025-11-14 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-08-31 12:30:14 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)
Takedown time:2 months, 14 days, 18 hours, 4 minutes Bad (down since 2025-11-14 06:34:55 UTC)
Tags:c2-monitor-auto dropped-by-amadey Socks5Systemz link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-31random.exeexe b38972558cf45f6f660d48e69ed191c8c7b80a6c19a86065057f18c53030c681Virustotal results 25.00%
2025-10-30random.exeexe 94fa33aaed208434ab40d7def4e4fc88cfab588c148e29084b2846a020696599Virustotal results 15.49% Socks5Systemz
2025-09-02random.exeexe b82a3834f67c52098d972b41f3a520728edd912538514f4e8388a20a4975f444Virustotal results 22.22% Socks5Systemz
2025-09-02random.exeexe f5305d6250527d7d97ac09dc8a1336394600a34e6a197cd54c06920d04b0807dVirustotal results 23.61% Socks5Systemz
2025-08-31random.exeexe b2504c032755327b307a3c7cfed7c7b750ef5d0acca59b2b4eabfecf37d648d9Virustotal results 22.22% Socks5Systemz