URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/3.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3809349
URL: http://178.16.54.109/3.exe
URL Status:Offline
Host: 178.16.54.109
Date added:2026-03-31 20:23:07 UTC
Last online:2026-05-07 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-03-31 20:24:12 UTC to abuse{at}omegatech[dot]sc)
Takedown time:1 month, 6 days, 10 hours, 57 minutes Bad (down since 2026-05-07 07:21:37 UTC)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-053.exeexe df67607c6f5c8b3262e7c18f07ccbd35728771bacc3b963418c204f4d39b3ff5n/aPhorpiex
2026-05-013.exeexe 9a71bf12bebafc0b33c3057a45323bd12a7e1450a6342360a7f426a30f9f7c5en/aPhorpiex
2026-04-233.exeexe 4910c586d5405fe9ca9c339ac2e3904f6eff8b8913605606fcc54f14810a29d4n/aPhorpiex
2026-04-223.exeexe 7548fc98358d15eaaa8cf8e29824af49d5d440ae991fed24ee8810002bf17cbcn/aPhorpiex
2026-04-203.exeexe 0bc6aad1faad13f94a2bba6a927a648fc49327ac224d0abe51530f91eb2d1a1cn/aPhorpiex
2026-04-063.exeexe 39c064b7e80aed53c6dd9eb06207b9cbd334a63b83e2fd5ead7727005a12a3b6n/aPhorpiex
2026-04-023.exeexe 981006af72be89f4b18b8b870aa77ea10a46a9373b621f655ba4a3c37cbfada1n/aPhorpiex
2026-03-313.exeexe c6bc3654e32d7d7c0b038e7c882705d169f87410ee7f2533a8c998b2209297bdn/aPhorpiex