URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3809352
URL: http://178.16.54.109/2.exe
URL Status:flame Online (spreading malware for 1 month, 20 days, 4 hours, 20 minutes)
Host: 178.16.54.109
Date added:2026-03-31 20:23:07 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-03-31 20:24:12 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-202.exeexe 1c512b9355ab3a505a38fee04dffe2cedccfadaf596df7dac4ae27dabf3631f1n/aPhorpiex
2026-05-162.exeexe f67df5b220f4ebb3158eecfe80bb7439334d61a6c22ddc27e755e0492b255fc1n/aPhorpiex
2026-05-122.exeexe f768aec48b9c966c34159db4ab0b3eed0b860c372a626afd63763baa7125a149n/aPhorpiex
2026-05-092.exeexe a8614ec9bc320861343c65a70595defe3d5b5b180eb91e7d9f38dd1c0cdd9e1fn/aPhorpiex
2026-05-072.exeexe 733f4abb59577e459509b7ac26c3c8d395ca2c3a8a9ed9f5f6c5a7eb4549b251n/aPhorpiex
2026-05-052.exeexe dd1bc922a0a06efbe87fc14187b6588e12089efcf938bbc3532602ea4b8b5157n/aPhorpiex
2026-05-012.exeexe 98af9f49fff912e959882946716b4cc9dd6ece9a57e836427ea4810d0cd3fb0en/aPhorpiex
2026-04-232.exeexe 4fe8620b653acea285b9dd46840140605054804eaa56941c5ef8a3c3bb37df1en/aPhorpiex
2026-04-222.exeexe 89c067ac857aa6ccc6e3ea1db06429e12acf9110bba7795c735451f3b99ed7a8n/aPhorpiex
2026-04-202.exeexe 0693d1659ff12cecfcc8ac404bec27c0eb9e2251c15a2049dc5e91268bf72e41n/aPhorpiex
2026-04-062.exeexe 0a5a72cc1d69e1f0c6113c84e634e9b9c82b8e7bc9d05b6732da3a4f5d81761dn/aPhorpiex
2026-04-052.exeexe 1ecc19bbef88b49ec956e09c61338b78f8bfcadac776834bb0dd037e9d6b2defn/aPhorpiex
2026-04-032.exeexe 11fbaa9f11fb195b7a2da2030dfd8e29770f46646fd783c4b969a79374be2cb2n/aPhorpiex
2026-04-022.exeexe 93a3412e427dbe3690a625219166d9e494593cd600932dface8584b3efe2b9adn/aPhorpiex
2026-03-312.exeexe 7bea83c3f297716ea901b8075d062bb02ce240ab6c5f6fa40ea8ce3f4ffef226n/aPhorpiex