URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/7782139129/nNM31RQ.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3631056
URL: http://178.16.55.189/files/7782139129/nNM31RQ.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-09-24 14:28:07 UTC
Last online:2025-10-10 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-24 14:29:09 UTC to abuse{at}metaspinner[dot]net)
Takedown time:16 days, 7 hours, 37 minutes Bad (down since 2025-10-10 22:06:48 UTC)
Tags:c2-monitor-auto dropped-by-amadey Socks5Systemz link Stealc Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-01nNM31RQ.exeexe c18f7ea329da96ac1a6f58cc10f749e5b2b3fe67b2ec7d8d345033e778213afbVirustotal results 12.50%Socks5Systemz
2025-09-29nNM31RQ.exeexe dcbe0940ea22adac4e6f0285483be719e5ec8c490ce56304e851378751c5a099Virustotal results 15.28%Vidar
2025-09-26nNM31RQ.exeexe 4bbc4243e4c86495a01cbdfd857dc4d101d5b51eb75c402bb206e2de4fd720c1Virustotal results 15.28%Stealc
2025-09-25nNM31RQ.exeexe ae9a6b6438f5d41b03219aa9e5ccfa77bd2fb0edbc39f4b6e98d28bbf7ea80e1Virustotal results 25.00%GoProxy
2025-09-24nNM31RQ.exeexe 6212a4070ac089ae3dce37b119a3d7e0ddc176d8de499ea8b7ba7be9bf619588Virustotal results 40.28%Vidar