URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/6849343518/3XnkGkr.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3664614
URL: http://178.16.55.189/files/6849343518/3XnkGkr.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-08 05:01:10 UTC
Last online:2025-10-10 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-08 05:02:20 UTC to abuse{at}metaspinner[dot]net)
Takedown time:2 days, 11 hours, 53 minutes Poor (down since 2025-10-10 16:55:56 UTC)
Tags:c2-monitor-auto CoinMiner dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-103XnkGkr.exeexe bde92e1dce25cae77e42162c51f9b176586675bf4f0df5fd077bfe675d4259f7Virustotal results 34.72%CoinMiner
2025-10-093XnkGkr.exeexe 6f37b4af91448efddfd2fd53dc563fcc4183713aca624969143dde63b66b4e0aVirustotal results 33.80% CoinMiner
2025-10-093XnkGkr.exeexe 5b01a94503b94a3950178604ad2bbc120863addcae2eec63e73999ee720d0d29Virustotal results 29.17% CoinMiner
2025-10-093XnkGkr.exeexe 52b9621bfec064b45bf496195a459658f086fe0d7023601c33291628aa5d7358Virustotal results 31.43% CoinMiner
2025-10-083XnkGkr.exeexe d5e9ba6cc1179411ddc174abe7e54ef88d55c589f0e3e8785bce6066a3782873Virustotal results 30.56%CoinMiner
2025-10-083XnkGkr.exeexe fa5586aad457da763e0b4c9f7d25dc078495ea210fc1bead9ea9adf1d491e4f2Virustotal results 27.78% CoinMiner
2025-10-083XnkGkr.exeexe 8832f5ecb1e61c79555bb01ba4b0567c3293400b64deb504349fde67d2c5f6d2Virustotal results 47.22%CoinMiner