URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/1242384682/gILdgOk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3679122
URL: http://178.16.55.189/files/1242384682/gILdgOk.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-16 04:04:07 UTC
Last online:2025-10-21 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-16 04:05:14 UTC to abuse{at}metaspinner[dot]net)
Takedown time:5 days, 1 hours, 30 minutes Bad (down since 2025-10-21 05:35:55 UTC)
Tags:c2-monitor-auto dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-18gILdgOk.exeexe a613fb7bf175b3f4706552753cec3dc5d9b26a43ed923f254ed2abd361652959Virustotal results 45.83%
2025-10-18gILdgOk.exeexe dcecfbc890d6eeb1a74c15e443df06f54b3be9d5adbf72b52955f8cee2d791f3Virustotal results 50.00% 
2025-10-16gILdgOk.exeexe 5e0c2821e18d0fb4589be172675e3bca4096e853cc2555cfff361e59db64c146Virustotal results 43.06%
2025-10-16gILdgOk.exeexe 0faded23a4dce8259edb506c13b5f74975e11b6a9ae469d1f49ea021549277a6Virustotal results 47.22%