URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/5900855435/YSdQm5F.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3712121
URL: http://178.16.55.189/files/5900855435/YSdQm5F.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-11-19 21:42:09 UTC
Last online:2025-12-21 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2025-11-19 21:43:14 UTC to abuse{at}lanedo[dot]net)
Takedown time:1 month, 1 days, 8 hours, 34 minutes Bad (down since 2025-12-21 06:17:31 UTC)
Tags:dropped-by-amadey fbf543 Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-19YSdQm5F.exeexe c27018bc8ebc4384941f642a88bb5355ec7f2bf94b8d94ba6f1ede008b4ac07en/a Vidar
2025-12-12YSdQm5F.exeexe 94d0d09187482f8be7308063ac67bb405accefc19b664aad8428e6ccee115bf8n/a Vidar
2025-12-10YSdQm5F.exeexe cf4c2a7a4cb079f71cca3697bfe5fa14f6e6e849e0fd1d18afb032c1c9b9eedcVirustotal results 48.61% Vidar
2025-12-06YSdQm5F.exeexe cd0e26e01fdf1a003d902710c02f009cf65031cdf4ebce73619615d5171ea4e0Virustotal results 50.00% Vidar
2025-11-25YSdQm5F.exeexe 0964b4808376b57789755867e3c9f587005ce87e4aee0eec882a699ca64f1342Virustotal results 44.62% Vidar
2025-11-19YSdQm5F.exeexe a3d738ac7f58dec46b30fa546987dafa8753b9324fa948cc84fb7ac51ef8ac7fn/aVidar