URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.200/app_win/random.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3619114
URL: http://178.16.54.200/app_win/random.exe
URL Status:Offline
Host: 178.16.54.200
Date added:2025-09-07 04:04:11 UTC
Last online:2025-11-14 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-07 04:05:12 UTC to abuse{at}metaspinner[dot]net)
Takedown time:2 months, 7 days, 20 hours, 16 minutes Bad (down since 2025-11-14 00:21:55 UTC)
Tags:Amadey c2-monitor-auto DarkVisionRAT dropped-by-amadey Fuery PDQConnect PureLogsStealer SheetRAT Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-17random.exeexe 9ff0ed219c56fb95f58e739e9eece082606da8556a9fccf344409daeae2a4eb7Virustotal results 39.44% PureLogsStealer
2025-09-17random.exeexe 934a7a6ed4ad95a8811c892a9da1bf576f82a7f5fb9bd7f03a367efd7d89c07dVirustotal results 54.17% Amadey
2025-09-17random.exeexe 707837ab12e3265c697210c168216999b7f82727119723d8d1006a4d46d3093an/aAmadey
2025-09-17random.exeexe 9eaace6e03a623f19b42824620b0c25d4187c905bf2b4a45f1a200d9750f4a07Virustotal results 51.39% Fuery
2025-09-17random.exeexe 0046ac156acfd377676b3b6a529e8dd7426d058f20a8ff445d47134b02e5c8c3n/aAmadey
2025-09-17random.exeexe 8d7365cc48461b00dd0ad82bc44b7a05ac2a9c31680b2c86d4e0bcd1a5a87067Virustotal results 51.39% Amadey
2025-09-16random.exeexe 6e823fcb84f802a443178df02eb1cd3ed62082a5f5227b86f093506353351b9fVirustotal results 45.83% Fuery
2025-09-16random.exeexe c4334489b8112ba58b4bb96a758ae07ce38ce976608c6accee6522c8cf0024bcVirustotal results 47.22% Amadey
2025-09-16random.exeexe 526b6ce033a3639f19f8486853ac99356dd90f09075f07579f8f9b1e9e530e2an/a Amadey
2025-09-16random.exeexe 452467956f142874056adaf483929ddeb2c9de3dba06474e6aa33ea1780c85eeVirustotal results 44.44% Amadey
2025-09-16random.exeexe 5fe8458656946a12d7eac289a4be70795687f11170d4f079fb49c2a3b06b2762n/a Amadey
2025-09-16random.exeexe c85c0e454ddc6684b4e577431f661b7fd6a5f6aa088258739a891302f630de68Virustotal results 38.89% Amadey
2025-09-15random.exeexe f3c2bee63d4dd75081878822b5bca8f78bd9c6eaf4aa4e1582c2a7c65c2fe114n/a SheetRAT
2025-09-15random.exeexe 65ba1bd46374d8ff4a10048190b08ed6caf531ddafbb4bba4230708dee48fedeVirustotal results 48.61% Amadey
2025-09-15random.exeexe 5cfc7216841e38a28c47d993a0d7f9751868611de5cf5062bd85c351e6a0cf41Virustotal results 44.83% Amadey
2025-09-15random.exeexe 848f8e2f82562e35a1492f19d8ff8dcc1506cfb6d13a9e9864e52194c12e75a9Virustotal results 45.83% PureLogsStealer
2025-09-15random.exeexe 9d6627aacc316d06f4168e45a8934761e9d12cb1056cc26093e7f970535cfb04Virustotal results 47.22% Amadey
2025-09-14random.exeexe 2007835d7cb7f59ddfd68986b3e28846e15274b5f8a93706b737e9a10ebc5a51n/a CredentialFlusher
2025-09-14random.exeexe 46cdf3efa0092626af28ed5d00b3eddca969b481d89080c3d0788124f985c3a3n/a CredentialFlusher
2025-09-14random.exeexe 9a8213cdc3db431325ca1e249d4c91f51e2855cb235a1f500da9dad8a4b773f4n/a Amadey
2025-09-14random.exeexe e2ab368dbc3683479f156446ff128b6baca7d6dc200aa7f6028dd2dab5d70497n/a CredentialFlusher
2025-09-14random.exeexe 453f4ec842998a8748f31bab15f6dae3d512581dbe68cd761cbb02d40ae62a08Virustotal results 44.44% CredentialFlusher
2025-09-14random.exeexe e9eaf190579ab0c8556e00cbe6a2bc2e6152247c1bf64239b454aea22dce1558Virustotal results 43.06% Amadey
2025-09-13random.exeexe 13b7299d85360722cfb6708db290e29dd7ce61f8273189dd17a3627f66e93333Virustotal results 57.75% Amadey
2025-09-13random.exeexe eb9e0e130ca4a4aa0473ece354f2e0c81ec1fce275e4388014098d9a2d4f054fVirustotal results 57.75% PureLogsStealer
2025-09-13random.exeexe e23436d76f6e6150991b83fe3989637a4b24d340045d42e4654798094a972cc5n/a Amadey
2025-09-13random.exeexe 6304f36b5baa132feee6ee53bf0874545cb31d99d2383183946c7189ab2155ccn/a PureLogsStealer
2025-09-12random.exeexe a1cf408946aebd1c2b43cf956262da4b3fabe37079f16dd736ef90bc151392c3Virustotal results 57.14% Amadey
2025-09-12random.exeexe 17f8a2abf75debe0751dde1ea157f89293ca75d6b1fb49dc8417b5411af190f1Virustotal results 56.34% Amadey
2025-09-12random.exeexe dff79b4e41a15196c5a3696623fb08954a8ae4b2448d1adf265276614cc9988bVirustotal results 56.34% Amadey
2025-09-12random.exeexe 68f3fbcc2c7864587867c406007cb726189c4e2257c8bfe0fcbe95644f183b97Virustotal results 57.75% Amadey
2025-09-12random.exeexe 1d9e8eb25c72138e7a3ad85bcd19a765bade731cd102092456f94dab3a211a47Virustotal results 58.57% Amadey
2025-09-12random.exeexe 8611c18b798fa81457583068d2b5825b1a5f69a787e71070b9ea7440c6e247baVirustotal results 57.75% PDQConnect
2025-09-12random.exeexe b79fef898880d03bb1b20c0f80196358c2b40b751f7628758d203d0cc6b58500Virustotal results 58.82% Amadey
2025-09-12random.exeexe d4684facb24bbdec0322bfe0022878c326b0403ef267bb80e7a2d342e3752a87n/a Amadey
2025-09-12random.exeexe f3c239c3be39862be02aa904748aa46b7fcc5ade520fcea424a6d3c88dd8faf2n/a Amadey
2025-09-11random.exeexe 18b46f4382510716f5659003575e63e62b50a403f4a78570b053e79ee2c07537n/aAmadey
2025-09-11random.exeexe 1bc3888a2da621de0e660bb2caa674270a1868dfeefaeec8bc10a8df6c0a159dVirustotal results 59.15% Amadey
2025-09-11random.exeexe 99baae6e6268917fcd38800a2a272e2c373d279c9c7fdff712773d6c17328c62n/a DarkVisionRAT
2025-09-11random.exeexe b27a9307ac96847554582ee1b84c006d36c29f41c222ccdc8d349c0d5e775729n/a Amadey
2025-09-10random.exeexe ac313710828c2f9c571a30cc6ab8783df184256e69140a7b909893d3c874e9c3Virustotal results 56.34% Amadey
2025-09-10random.exeexe a1929d1fdd2165a86afcfc232c20aaa5a63e3a2cdbd3fff7104fbf77af191c69Virustotal results 56.34% Amadey
2025-09-10random.exeexe 78c15fe99029971da65e6b8fb5bfd9aacdb3fddfc51aeeefb86118c35a22afe9Virustotal results 52.24% Amadey
2025-09-10random.exeexe e26939d828811c563ec325b50b48e277c9b7b08c6dcc2efc741fe704198e83f9Virustotal results 53.52%Amadey
2025-09-09random.exeexe 29c8ba9dbd758d391e658f1ff36fab249ef5c2d1a85a15d3a912c91c7c89b6f4Virustotal results 54.93% Amadey
2025-09-09random.exeexe 5ae88cd51d2e3ed742036edc37cfa7c5a8ea3ac7b0e7cbce6a3cb5157fa72f73Virustotal results 56.34%Amadey
2025-09-09random.exeexe fba71471e39aa6f5fad6db81392302b924f137d256ad13836fa2bff6b62e869aVirustotal results 54.93% Amadey
2025-09-09random.exeexe 1a415d27f841721da64afea8855f1562e63b3b515360f0db82e6084ecb551341Virustotal results 58.82% Amadey
2025-09-09random.exeexe 1c52c7f629bf1cfaa4b43e42174825cbd3e24cedd40b8fc63281b29bfe9f4e5eVirustotal results 57.75% Amadey
2025-09-09random.exeexe dcc2de9a387102f876834661c9328bacd36f28f41857f963e880ada0eed0f78aVirustotal results 55.71%Vidar
2025-09-08random.exeexe dd4095557998cdfb6675897f18a2c0a993e4f810e2043a32a6ebca6b25b8ce84Virustotal results 56.34% Amadey
2025-09-08random.exeexe c34e870017753ac448f08b506a13d1236d081a33fc61b7b2a96e30c659f03539Virustotal results 57.75% Amadey
2025-09-08random.exeexe 6ba0aa6a5d2ec13c4368a36ecb677d03aef21bc17b140c44e9709feed9e0742dVirustotal results 53.03% Amadey
2025-09-08random.exeexe 35c110c30e3c297fae36e6708a57e7c022d8d311596b5fa9d7f33825b5ce1cd2Virustotal results 55.71% Amadey
2025-09-07random.exeexe 9e567b22046308b8877a26392f43cc41f6bc2ae23f98cff9ecdfbd4cfb17d91aVirustotal results 53.52% Amadey
2025-09-07random.exeexe de5439de8e4008d4189ea5bb97f617694f9c12bac77acc0ecf840828a0a831d2Virustotal results 56.34% Amadey
2025-09-07random.exeexe e5ecd42dec55a0785fce2106a814acf605818904da423c256e024fb654e3862bVirustotal results 55.56% Amadey
2025-09-07random.exeexe 315a8559935ef97b4fe5128d8ab92ba2a168be2519308e37db3ddf3a797e4902n/aAmadey