URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.200/files/8233900432/XaUfT3G.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3625187
URL: http://178.16.54.200/files/8233900432/XaUfT3G.exe
URL Status:Offline
Host: 178.16.54.200
Date added:2025-09-16 17:56:06 UTC
Last online:2025-11-05 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-16 17:57:10 UTC to abuse{at}metaspinner[dot]net)
Takedown time:1 month, 19 days, 18 hours, 56 minutes Bad (down since 2025-11-05 12:53:46 UTC)
Tags:c2-monitor-auto dropped-by-amadey Fuery

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-23XaUfT3G.exeexe 71ba2774dab0b4aa858921c12918e743db695722c99d15a3adc345f84efbc74bn/aFuery
2025-09-22XaUfT3G.exeexe e92b9040dcc7e8c33c7a6b9db3495b2dbff3ebb70b8fdae645521a511f9c6f87Virustotal results 29.17%Fuery
2025-09-19XaUfT3G.exeexe 9c0d7aefababf691ddb1e9a932679470c95223cee339fdf2d65ec28964dd38a2Virustotal results 29.17%Fuery
2025-09-16XaUfT3G.exeexe 8f217d94322c29d45433f6a4d59fb09d2876a2b09bee3097b0047b7522a5df74Virustotal results 45.83%