URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.200/files/6331503294/dPzCoRY.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3697136
URL: http://178.16.54.200/files/6331503294/dPzCoRY.exe
URL Status:Offline
Host: 178.16.54.200
Date added:2025-11-05 13:15:10 UTC
Last online:2025-11-06 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-11-05 13:16:20 UTC to abuse{at}lanedo[dot]net)
Takedown time:1 day, 5 hours, 37 minutes Poor (down since 2025-11-06 18:54:05 UTC)
Tags:c2-monitor-auto dropped-by-amadey

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-06dPzCoRY.exeexe f3e06b8e195ef364d6ef3d42cf07e11f0384c9c6fc17eb9b2d8d97cd8176286fVirustotal results 26.09% Kamasers
2025-11-06dPzCoRY.exeexe b3aa095645a2f14144bf9dc1c70c6c5ebba8cc130df6dfedde999324a438f7d5n/a Kamasers
2025-11-06dPzCoRY.exeexe 2e42313ceeef02d59f20aaa449359d1e2158f32aeee1815a056e7bba64f27e00Virustotal results 25.93% Kamasers
2025-11-05dPzCoRY.exeexe 1462b098d2c87d2af6b21a0ad527dcbd885326a576b412381082f5515364134eVirustotal results 20.00% Kamasers
2025-11-05dPzCoRY.exeexe 4d69e1c88a9ca803fd7f02395dc2f3a737c32a13fe6ee801cb908fb075cd0e86Virustotal results 47.89%Kamasers