URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/5296057416/ef3Z01h.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3668657
URL: http://178.16.55.189/files/5296057416/ef3Z01h.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-11 18:24:07 UTC
Last online:2025-10-25 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-11 18:25:15 UTC to abuse{at}metaspinner[dot]net)
Takedown time:13 days, 22 hours, 25 minutes Bad (down since 2025-10-25 16:50:31 UTC)
Tags:c2-monitor-auto dropped-by-amadey Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-23ef3Z01h.exeexe bf0eac63fdcf71727827ea88d076a3dd7f109dcf2bbffb67b7dacc7b42861a59Virustotal results 44.44%Rhadamanthys
2025-10-17ef3Z01h.exeexe 6c0c809060dca43795f724aeae924802bc4cac170c48053a74f9c97d85460573n/a
2025-10-13ef3Z01h.exeexe a8503016d7231bd7832b33baccb5ed771a5c3cba0ff1cd80133a334661e04eb8Virustotal results 44.44%
2025-10-11ef3Z01h.exeexe 9d76c0ca960c251fa95e9414b787f440382e6154773750994408fb9b5f2557d2Virustotal results 45.83%