URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/7559408112/3rLRc0r.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3687920
URL: http://178.16.55.189/files/7559408112/3rLRc0r.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-26 13:10:09 UTC
Last online:2025-11-02 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-26 13:11:20 UTC to abuse{at}lanedo[dot]net)
Takedown time:7 days, 9 hours, 58 minutes Bad (down since 2025-11-02 23:09:48 UTC)
Tags:c2-monitor-auto dropped-by-amadey Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-013rLRc0r.exeexe 34990bb4e4e98cff2866006bff4b27269e62f40a41897a624a460bd3e39903een/a Rhadamanthys
2025-10-303rLRc0r.exeexe 4ede371503e24bc910542dd8164deb8e8395ee5f0e0d0cc0408f51a17f40ace1n/aRhadamanthys
2025-10-293rLRc0r.exeexe 3012d2049967c5b3907526469d856d560398dce522aa9fe061f96f11259c7a6dn/a Rhadamanthys
2025-10-283rLRc0r.exeexe ac3d323fbd142bc475632b55187be01d312fad230e04a3e1deed6a8732db09aaVirustotal results 22.54% Rhadamanthys
2025-10-263rLRc0r.exeexe 068415ce8f9a0e490131170a98c363d7d5055987dda58ae2168f71a8b600cd84Virustotal results 21.13%Rhadamanthys