URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.200/files/5917492177/QTu8SCx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3625562
URL: http://178.16.54.200/files/5917492177/QTu8SCx.exe
URL Status:Offline
Host: 178.16.54.200
Date added:2025-09-17 12:20:07 UTC
Last online:2025-09-18 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-17 12:21:14 UTC to abuse{at}metaspinner[dot]net)
Takedown time:1 day, 0 hours, 26 minutes Poor (down since 2025-09-18 12:47:42 UTC)
Tags:c2-monitor-auto dropped-by-amadey Rhadamanthys Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-17QTu8SCx.exeexe 8241a68dea2bf5c1a604633c978e7f1a3fc90e5b8cfc0e6225fe63b25ad16cc9Virustotal results 31.94%Stealc
2025-09-17QTu8SCx.exeexe 3c08a809156756e68bd0574e79a21bd4644d1f632bce529f1f7bce43ac05e978Virustotal results 40.28%Rhadamanthys
2025-09-17QTu8SCx.exeexe 31faa7175a8e57fa345c395bf0490d3437b8f2117b193948a7f3789d3fc9ef7eVirustotal results 34.29%Rhadamanthys