URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3809348
URL: http://178.16.54.109/1.exe
URL Status:flame Online (spreading malware for 27 days, 2 hours, 55 minutes)
Host: 178.16.54.109
Date added:2026-03-31 20:23:07 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-03-31 20:24:12 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-231.exeexe 5fb0a8edd0ece76b52b8bb32dd9777255585237c511a54d2bc3875796db5c361n/aPhorpiex
2026-04-221.exeexe cdf876273c6175f4cdbaacd6ab361ffde60edb2ac3ffa2bcf8e74c5a18f4e462n/aPhorpiex
2026-04-201.exeexe 30c1114e05874981661292fcca63241571eb0186175fcddc61cbc99fd3e52d7bn/aPhorpiex
2026-04-061.exeexe 716eeed4288a841e5be39da871136976c731d2aa67b3b9c0a4679b3e4834685bn/aPhorpiex
2026-04-031.exeexe 0be4b693eea4b551de0044d8303c31749df873e005756db5a1d68db8c9a516fdn/aPhorpiex
2026-04-021.exeexe cb8ed8faa43d39df05659bd1396cc2d037401b386c05471b2ce9f0dfac86c711n/aPhorpiex
2026-03-311.exeexe 5fcbcff1557b61cacdedf23dfdabe5d303a9edafd911d0c8f7d7cecf0fa2ad2cn/aPhorpiex