URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3809349
URL: http://178.16.54.109/3.exe
URL Status:flame Online (spreading malware for 7 days, 9 hours, 37 minutes)
Host: 178.16.54.109
Date added:2026-03-31 20:23:07 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-03-31 20:24:12 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-063.exeexe 39c064b7e80aed53c6dd9eb06207b9cbd334a63b83e2fd5ead7727005a12a3b6n/aPhorpiex
2026-04-023.exeexe 981006af72be89f4b18b8b870aa77ea10a46a9373b621f655ba4a3c37cbfada1n/aPhorpiex
2026-03-313.exeexe c6bc3654e32d7d7c0b038e7c882705d169f87410ee7f2533a8c998b2209297bdn/aPhorpiex