URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.53.7/zocp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3688580
URL: http://178.16.53.7/zocp.exe
URL Status:flame Online (spreading malware for 23 days, 17 hours, 36 minutes)
Host: 178.16.53.7
Date added:2025-10-27 12:04:08 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-27 12:05:25 UTC to abuse{at}lanedo[dot]net)
Tags:c2-monitor-auto dropped-by-amadey Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-28zocp.exeexe f3c3968ee7c1ed263eb6584e2a694d5c611fa40e98d33ed2d4d3b9eef0135276Virustotal results 56.34% Rhadamanthys
2025-10-27zocp.exeexe 36eeed998c47e1eadbd363a269e778dc1c0bd21c192180de220af130d59d74feVirustotal results 46.48%Rhadamanthys