URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/newtpp.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3688690
URL: http://178.16.54.109/newtpp.exe
URL Status:flame Online (spreading malware for 1 month, 13 days, 16 hours, 39 minutes)
Host: 178.16.54.109
Date added:2025-10-27 14:13:06 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-10-27 14:14:13 UTC to abuse{at}lanedo[dot]net)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-18newtpp.exeexe 51455bce4f49061e859cb4cc830f9d4b3478f9c7082b7b9f55febc68234a06f7Virustotal results 62.50%Phorpiex
2025-11-14newtpp.exeexe 7436220538e6cded0c499167424975a2aacf93217dca40c683f0610b4f3eb3b7Virustotal results 63.89%Phorpiex
2025-11-04newtpp.exeexe 805db6f001167b526485cfb9bd6fac5dbe7737af6a46100cc69348c9145bee4aVirustotal results 56.25%Phorpiex
2025-10-27newtpp.exeexe 926e7a5fc2df14280ddb9fad2a6a3a8101c4024cbce128f9feacb0f0c1e2070eVirustotal results 77.78%Phorpiex