URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.200/files/174733404/PsCMIRi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3617786
URL: http://178.16.54.200/files/174733404/PsCMIRi.exe
URL Status:Offline
Host: 178.16.54.200
Date added:2025-09-05 14:55:11 UTC
Last online:2025-09-13 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-05 14:56:13 UTC to abuse{at}metaspinner[dot]net)
Takedown time:8 days, 5 hours, 51 minutes Bad (down since 2025-09-13 20:47:48 UTC)
Tags:c2-monitor-auto dropped-by-amadey Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-12PsCMIRi.exeexe 6ae3e47a682279854e2c2ecbbe8fcddd5a763a3506089e74454c8fff027301adVirustotal results 48.57%Rhadamanthys
2025-09-10PsCMIRi.exeexe 8666d19b603834a8f842a86faddbbf0d8aeec003ff0b0152cff4c7fef936573dVirustotal results 45.83%Rhadamanthys
2025-09-09PsCMIRi.exeexe 9fa816137ebc8147afb914999724d61d979c56b2fb5680a8f38f36a2e173174dVirustotal results 45.83%Rhadamanthys
2025-09-08PsCMIRi.exeexe a5809a42fba08fa4ce38ae0ab74b433fe91826de4296c147fc4214eee86dc919Virustotal results 45.83%Rhadamanthys
2025-09-07PsCMIRi.exeexe d5d1a3362fe4e63bca40faa5c0a201a56c76cd27c1ce4c0b11a6bc13c3e19941Virustotal results 45.83%
2025-09-06PsCMIRi.exeexe fdfbc1ca939418ba3fe30ef9daca82ae843fec06997f3a21d70aeb9c18f997b6Virustotal results 44.44%Rhadamanthys
2025-09-05PsCMIRi.exeexe 155f53209e7e4aacf1efb3c929a2aaa659f98f9dd3ff703d0eed9ff7379a7da3Virustotal results 68.06%Rhadamanthys