URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/7305855948/AP7EuAF.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3680377
URL: http://178.16.55.189/files/7305855948/AP7EuAF.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-18 04:10:09 UTC
Last online:2025-10-20 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-18 04:11:13 UTC to abuse{at}lanedo[dot]net)
Takedown time:2 days, 0 hours, 0 minutes Poor (down since 2025-10-20 04:11:31 UTC)
Tags:BlackMatter c2-monitor-auto dropped-by-amadey Rhadamanthys SalatStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-19AP7EuAF.exeexe 7df420f9c3846e357c6667378c6430fb32f9c964f4cc48838e61d2ba1d019519Virustotal results 87.69%Ransomware.BlackMatter
2025-10-18AP7EuAF.exeexe 78fa4293b7004d035265bd615b0c4676255ccf4e6e579984c0bb47cb28b1524dVirustotal results 37.50%Rhadamanthys
2025-10-18AP7EuAF.exeexe 42e727d45f28d8ecccd7d421d7b0e80d12cb7fd4e7e4238ae7168aa62d56a2ceVirustotal results 45.83% SalatStealer
2025-10-18AP7EuAF.exeexe 29c0d4984b75249ca32eb674095996913758b9b91746c788db80a419dd984e50Virustotal results 52.78%SalatStealer