URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/5917492177/2f34b5X.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3634310
URL: http://178.16.55.189/files/5917492177/2f34b5X.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-09-29 04:09:08 UTC
Last online:2025-10-03 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-09-29 04:10:11 UTC to abuse{at}metaspinner[dot]net)
Takedown time:4 days, 2 hours, 38 minutes Bad (down since 2025-10-03 06:48:32 UTC)
Tags:c2-monitor-auto dropped-by-amadey Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-022f34b5X.exeexe 864871d4967db39a0c2117d47bae57456526d891db9f1a3ad1cc6fc1ac85e7b1Virustotal results 59.72%Stealc
2025-10-012f34b5X.exeexe 23f529a02ef4ecfefc10d5610520765c0c85fc7b385768ffc7b02a976718c8d2Virustotal results 51.39%Stealc
2025-09-302f34b5X.exeexe 6e578f0eab7160cf75a0fd2c0c509deac564c986454d929d67f400649cb086faVirustotal results 51.39%Stealc
2025-09-292f34b5X.exeexe 2dd15d74151531c7156a20297429cd371a603b458326d7972b2a95fed0e37ad4Virustotal results 44.44%Stealc
2025-09-292f34b5X.exeexe a6ab3c8bfe73f7041dfdf9399d13c4281a7a6173e9e6f50ca7901687226c27c1Virustotal results 26.39%Stealc