URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/502259649/valPntR.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3694791
URL: http://178.16.55.189/files/502259649/valPntR.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-11-03 09:20:08 UTC
Last online:2025-11-04 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-11-03 09:21:18 UTC to abuse{at}lanedo[dot]net)
Takedown time:1 day, 14 hours, 36 minutes Poor (down since 2025-11-04 23:57:28 UTC)
Tags:c2-monitor-auto dropped-by-amadey Rhadamanthys

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-04valPntR.exeexe 32fe6de0c298c88cb6c1b6438296d005d3c4e862439f1417aeb23a278508360an/a Rhadamanthys
2025-11-03valPntR.exeexe 3cf2b0e4e30be8c952b2bd34fbbe0646e2f65bc6bf71e09275440f6e4bb6d869Virustotal results 58.33% 
2025-11-03valPntR.exeexe 684e2075f1c3ea2bfa49f3a1012a5d241d576c84545b283cc8541bc1c286b585n/a