URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.55.189/files/748049926/JI9fbje.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3732458
URL: http://178.16.55.189/files/748049926/JI9fbje.exe
URL Status:flame Online (spreading malware for 4 days, 6 hours, 41 minutes)
Host: 178.16.55.189
Date added:2025-12-12 18:44:09 UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-12-12 18:45:15 UTC to abuse{at}lanedo[dot]net)
Tags:c2-monitor-auto dropped-by-amadey GoProxy

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-15JI9fbje.exeexe 6e3647ad54e590d3a3b791a25739b73d4e155984c9d12cce6cb4d19e6d47b4fcn/aGoProxy
2025-12-14JI9fbje.exeexe 199ec99e17d06bc96ca6171960d31657dcc7f2ef57ee9e26054331848ef331ccn/aGoProxy
2025-12-14JI9fbje.exeexe 42ba972b74d4b798fb8b38110d38d01a3ad424fa6077ba4da5a0a2b531064656n/a GoProxy
2025-12-13JI9fbje.exeexe 4541914bed8fd6b53b36f70979abb3dd4ffc2edde90cb918c2b4502dd3595753n/a GoProxy
2025-12-12JI9fbje.exeexe 3ce47d62658d779a563adf6da6b440fff6bdd556d504773f42f6e30245b6550fn/aGoProxy