URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/8352719041/41lglxP.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3730355
URL: http://178.16.55.189/files/8352719041/41lglxP.exe
URL Status:Offline
Host: 178.16.55.189
Date added:2025-12-10 05:53:12 UTC
Last online:2025-12-14 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-12-10 05:54:18 UTC to abuse{at}lanedo[dot]net)
Takedown time:3 days, 18 hours, 20 minutes Bad (down since 2025-12-14 00:14:18 UTC)
Tags:c2-monitor-auto dropped-by-amadey OffLoader ResolverRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-1241lglxP.exeexe 9e63c3fcedbfe5f72b32fa92e5e236e25502e8645093e2ca200b177c3374e5b7n/a OffLoader
2025-12-1141lglxP.exeexe 57dae232eb671afd4fff507b4449b8dab20466e643a620f59bd268941491fc08n/a 
2025-12-1041lglxP.exeexe 3d0d91d0fcdd16e7bb270c57dd739d4ee33b2ca70564f9bfa7dc8c6a86b1b7cbn/a
2025-12-1041lglxP.exeexe 0bf636489b239160bcd7a08ded2f7f8ba0fecf881828794d141223533a912c23Virustotal results 22.22%ResolverRAT