URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/8061402479/xO50QoO.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3615935
URL: http://178.16.55.189/files/8061402479/xO50QoO.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-09-03 04:02:11 UTC
Last online:2025-09-24 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-03 04:03:08 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)
Takedown time:21 days, 9 hours, 29 minutes Bad (down since 2025-09-24 13:33:04 UTC)
Tags:c2-monitor-auto dropped-by-amadey LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-05xO50QoO.exeexe 837a5ae11a55ee51f20f6e1377a714730fe4df1914d22529064a70008393dca8Virustotal results 36.11%Stealc
2025-09-05xO50QoO.exeexe ea37de23a99f57a12361c094bfedc9cb91356f1d729a313ae68fcb86febf5701Virustotal results 29.58%LummaStealer
2025-09-04xO50QoO.exeexe d20503a6c683c4cfddc10051531db2ab1b43be7d1b786d71f65938ce84812bbeVirustotal results 30.99%LummaStealer
2025-09-04xO50QoO.exeexe 31294603a887756a97d1f8b3b5f8a0f3ece03907448ea717dfc8b4d017be5897Virustotal results 19.72%Stealc
2025-09-04xO50QoO.exeexe f234f9b798ad23cb4bafca43e166a651ae2bb52bd7df8b004ebb163f0a87cbfdn/a
2025-09-03xO50QoO.exeexe 3c72e373c64cba0ab7f72702e009ac380a77a45d2de4c4dee73d0c5e4ec5bd90Virustotal results 12.50%
2025-09-03xO50QoO.exeexe 8b980a3e33269d3784065e3786e80bae89ab3bd1bdf94a2d370e39111f7f45e3Virustotal results 26.39%