URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/6331503294/nGFFa2Q.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3690132
URL: http://178.16.55.189/files/6331503294/nGFFa2Q.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-10-29 05:47:07 UTC
Last online:2025-11-01 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-10-29 05:48:15 UTC to abuse{at}lanedo[dot]net)
Takedown time:3 days, 1 hours, 45 minutes Bad (down since 2025-11-01 07:33:58 UTC)
Tags:c2-monitor-auto dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-01nGFFa2Q.exeexe e97b9a9b4c4a6c876aec842a23f20f8a581ab7b4801500d81c81b3ee0a75a92aVirustotal results 29.58% Kamasers
2025-10-31nGFFa2Q.exeexe 3227540da89670874293cc6e3254294d65171786368c6f295d54f3560d595c11n/a Kamasers
2025-10-31nGFFa2Q.exeexe ac086200d0be8b8808403a67d42bfb4ec21fa7b43e10b4ce524bf43b956b560en/a Kamasers
2025-10-31nGFFa2Q.exeexe 5c75b94e3577d35a616fe17e92f78149fb0a87f79d67fa6e5dd33d77433b7a1fVirustotal results 28.99% Kamasers
2025-10-31nGFFa2Q.exeexe 693b0bd511c863bccf221b0f290d92a6a4cc0c705ae0bc010e917489b5af70e8Virustotal results 18.57%Kamasers
2025-10-30nGFFa2Q.exeexe bdbc0b640c52f4806c22dac829a9e5c5a083f243542e4ab2f7cea6bcc4545753Virustotal results 29.85%Kamasers
2025-10-30nGFFa2Q.exeexe 2573c3fb03cdeb8c429095148eacc650c8a4ed3a63139bd9b7a69f4f3c933f97Virustotal results 30.99% Kamasers
2025-10-29nGFFa2Q.exeexe bdbfc468baddb50762d7c0afb21884b8d9bd73ec6338747ba26a991993117f95Virustotal results 27.14% Kamasers
2025-10-29nGFFa2Q.exeexe b168818b91aaa2280487bc2e0250a56accf245a06bd721d7e141b33ce676693bn/aKamasers
2025-10-29nGFFa2Q.exeexe 5d5923066946e39fee640157d70ad3e2e39c5450eee0b3cd9ba230f4e4fb4202Virustotal results 30.99%Kamasers
2025-10-29nGFFa2Q.exeexe 49dab8647d7a28c0b75ecb99e06f70ae3c9bc7ed2e91b2c0ab2ce769891c83c4Virustotal results 29.58%Kamasers