URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/6536110418/7B1WGaP.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3666169
URL: http://178.16.55.189/files/6536110418/7B1WGaP.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-09 11:47:10 UTC
Last online:2025-10-09 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-09 12:33:10 UTC to abuse{at}metaspinner[dot]net)
Takedown time:10 hours, 55 minutes Good (down since 2025-10-09 23:28:40 UTC)
Tags:c2-monitor-auto dropped-by-amadey MaskGramStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-097B1WGaP.exeexe 97480113e490f98d00cc5c46c6a28c252ce1fabb5b8c698844bc6ae8df11c6b2Virustotal results 30.56% Stealc
2025-10-097B1WGaP.exeexe 17e23d90b2fe73eb79e18325e033c9aeb369d4b4c5b0a5c68590903de19a2e36Virustotal results 18.06%MaskGramStealer