URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/8172919016/81EhfrW.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3632846
URL: http://178.16.55.189/files/8172919016/81EhfrW.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-09-27 04:07:13 UTC
Last online:2025-09-29 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-27 04:08:10 UTC to abuse{at}metaspinner[dot]net)
Takedown time:2 days, 13 hours, 2 minutes Poor (down since 2025-09-29 17:10:53 UTC)
Tags:c2-monitor-auto dropped-by-amadey quantloader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-2781EhfrW.exeexe 36d21dd83d7c44184e0da1c744c060a883bcdf58abf91340bf3cbf27e0640be5Virustotal results 39.44%QuantLoader
2025-09-2781EhfrW.exeexe b8ab6e0c2de56ca73faf37c9abdc67bcd85985d70d24990fcafcba390050ce22Virustotal results 40.28% 
2025-09-2781EhfrW.exeexe 9a9e66b9b5bb23578a3c3c5bccc7774cda6a321608cb37c53a7886e8f49e2e6fVirustotal results 29.17% 
2025-09-2781EhfrW.exeexe 569d663518b0ce51c7411589cdf5dadb21a9eb2883582c3664c3df0ca2d071adVirustotal results 37.50%