URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/7.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3812664
URL: http://178.16.54.109/7.exe
URL Status:flame Online (spreading malware for 1 month, 0 days, 5 hours, 36 minutes)
Host: 178.16.54.109
Date added:2026-04-06 02:19:06 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-04-06 02:20:17 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-057.exeexe f2ea36a0f395de8b623a4bc7a148acfed82941ec78d1d7464e7cfa52fac6ff3dn/aPhorpiex
2026-05-057.exeexe 7891b653670e57e0dc4190226cccc0db6d7a29dd314db2ff98c4def828dc0cbbn/aPhorpiex
2026-05-017.exeexe 4ef867a958a45fa8a8f570d0c8dc8385198623c29289b09c3d37412e873c22f3n/aPhorpiex
2026-04-237.exeexe a20ac10f807be5f93843283a92d8792310b2fddbad783cd305c130fb7835ef0cn/aPhorpiex
2026-04-227.exeexe eaa6fc0957da85282da01af471314a842f103b810006c224e2fb514ed0589660n/aPhorpiex
2026-04-067.exeexe 81049439863f9d4166385718d23ad2e0a82ded1a4ffd351a33b6cc741d3760aen/aPhorpiex