URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/9.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3833909
URL: http://178.16.54.109/9.exe
URL Status:flame Online (spreading malware for 9 days, 2 hours, 32 minutes)
Host: 178.16.54.109
Date added:2026-04-28 16:11:07 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-04-28 16:12:12 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-079.exeexe 3badd58c276f867d0ce687a120956d6fa8810a12d14c7b6fe885c920230c9479n/aPhorpiex
2026-05-059.exeexe 026b48e79093531e6ca25d244fe3426779bdb84aee746852a59cc91621828b5en/aPhorpiex
2026-05-019.exeexe 6ee3905d8e71ee08d7cba90d3ef4d9ddb5aae1f977c272d2e0f0061e35319244n/aPhorpiex
2026-04-289.exeexe c9984870e1caada45b1ea9dc1f9829bfd342f4adbbc586398e443d765e28371an/aPhorpiex