URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.53.7/4.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3617560
URL: http://178.16.53.7/4.exe
URL Status:flame Online (spreading malware for 2 months, 16 days, 0 hours, 9 minutes)
Host: 178.16.53.7
Date added:2025-09-05 04:16:06 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-09-05 04:17:10 UTC to abuse{at}metaspinner[dot]net)
Tags:dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-164.exeexe ee0b03e8ae8b2be7f26a1533c26199acb0281b80df39651d92665d105d3582c4Virustotal results 37.50% 
2025-09-054.exeexe 86b8e95a757e682c640e9d755c1e74db5911313821daea67e07b4fc0c403b940n/a