URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.53.7/3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3615073
URL: http://178.16.53.7/3.exe
URL Status:flame Online (spreading malware for 2 months, 19 days, 23 hours, 35 minutes)
Host: 178.16.53.7
Date added:2025-09-01 06:05:14 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-01 06:06:10 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-153.exeexe 1ad1479dfbb71fd43603e1f71d7ab5de19cdd5dbb4dbf86d1d03c9a439e3d532Virustotal results 37.50% 
2025-09-073.exeexe fc8197adf50313fa8d889ded2ed96600a9d946caa01448d21b207bfe94ccff0eVirustotal results 43.06%
2025-09-063.exeexe 81997765ffabdaab5417720fd9202834a0cfef810b769f6a1300b0e32694e5cbVirustotal results 43.06%
2025-09-033.exeexe 6ee280efcad12a54fe6ab0dcf5db5f3b18658a9bce5c039cf0e1751804f5e617Virustotal results 41.67%
2025-09-013.exeexe e0e90138c11649dfd51bc8cfe66a9d9eeef122f2aeed4258668915d89661787eVirustotal results 42.25%