URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.200/files/7453936223/RenT7Wg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3618122
URL: http://178.16.54.200/files/7453936223/RenT7Wg.exe
URL Status:Offline
Host: 178.16.54.200
Date added:2025-09-06 04:01:06 UTC
Last online:2025-11-05 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-09-06 04:02:11 UTC to abuse{at}metaspinner[dot]net)
Takedown time:2 months, 0 days, 10 hours, 35 minutes Bad (down since 2025-11-05 14:37:55 UTC)
Tags:dropped-by-amadey LummaStealer Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-25RenT7Wg.exeexe dbab3fbea6138e57e996045a93a3105d86e5e659bbc311d71a4e7bcc698dc353Virustotal results 63.89% Vidar
2025-09-24RenT7Wg.exeexe 809b52d8726139b2831f245dc3267e042eeba9db0d896498bdcb11489f533ee3n/a Vidar
2025-09-10RenT7Wg.exeexe e3356215981ea7908f0c10e174a8d93db48492f5e9ee0242d416ac8e3d81421fVirustotal results 40.28%LummaStealer
2025-09-08RenT7Wg.exeexe 7ec7262762abc29e55cb6e77d8674f7bd75cc9da395fea1a959e4eff362e2d48Virustotal results 55.56%LummaStealer
2025-09-06RenT7Wg.exeexe 61b0374c1c5cb8194b2bba4ca0d8b05417cbc442cfd82ab62e083b13d2ab15ceVirustotal results 40.28%LummaStealer
2025-09-06RenT7Wg.exeexe ab6d7532424d66be8fd4f644fc8c83c1ed2882e614f080d4051e247c06719512Virustotal results 75.00%LummaStealer