URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/8434554557/ckHhVTd.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3659905
URL: http://178.16.55.189/files/8434554557/ckHhVTd.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-06 04:18:06 UTC
Last online:2025-10-23 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-06 04:19:16 UTC to abuse{at}metaspinner[dot]net)
Takedown time:17 days, 13 hours, 37 minutes Bad (down since 2025-10-23 17:56:38 UTC)
Tags:c2-monitor-auto donutloader dropped-by-amadey PureLogsStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-17ckHhVTd.exeexe 2fe4e0a7ee928ab312637f4734a3b66038f12fb48415e5675c345431fac3c021Virustotal results 28.17%PureLogsStealer
2025-10-15ckHhVTd.exeexe 68ceae64d7bd6c09e24598da9a4ab1e52f08a896384e8d3bc725c3688298d1bbVirustotal results 18.06%PureLogsStealer
2025-10-13ckHhVTd.exeexe 1ee66c400eff12bfaf129aa702b60f747a9b777f73b9d2df8e50c7fbd4e86472Virustotal results 15.28%DonutLoader
2025-10-09ckHhVTd.exeexe 53d86c40bff1ab25685e7fecff77b573ce72cb839f83139edcd27ff60740d4afn/aPureLogsStealer
2025-10-07ckHhVTd.exeexe b5791e37504c3e702aaa6f71344bef822f075897f397ac552856f32013d6240cVirustotal results 16.67%PureLogsStealer
2025-10-06ckHhVTd.exeexe 217f193c08ad80f6cc405608b6f67a5ce7e0c4074e5c2d4be6e758b7694337b5Virustotal results 40.28%PureLogsStealer