URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.109/12.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3847114
URL: http://178.16.54.109/12.exe
URL Status:flame Online (spreading malware for 2 months, 15 days, 18 hours, 19 minutes)
Host: 178.16.54.109
Date added:2026-05-15 04:11:07 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-05-15 04:12:13 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-Phorpiex phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-2912.exeexe 0ecc8ca00c5f331e2bb732b2295c8e019592d333c2ae0270653bc2900384a700n/aPhorpiex
2026-07-2912.exeexe 96aa9b5fcc9f02bf0879ae9b1e088b3f8dc978ec323da003b194fb660acd0713n/aPhorpiex
2026-07-2912.exeexe 27c74bd229840f70bb35cf28c00756d6fda16b0371789df00dd718c901041131n/aPhorpiex
2026-06-0512.exeexe eb5285d7ef5971067805bffe6658f26bcead1a53a054f257cc80c7e034c9231bn/aPhorpiex
2026-05-2912.exeexe 041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dcn/aPhorpiex
2026-05-2612.exeexe edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19n/aPhorpiex
2026-05-2512.exeexe f0a2e52f99091dc85534cc8b3b300327bfddc1a91eb9dfef9a793e40fdbeadebn/aPhorpiex
2026-05-2312.exeexe 0c90e66538809a106c820738fe52e5c71100b860d71c77604e8b8915d18a0133n/aPhorpiex
2026-05-2012.exeexe f5a0bdd90c40986a317a98d7278c127fb9991021a0f93cf31e07c62d19f9e48en/aPhorpiex
2026-05-1612.exeexe 8509cbea3a8fc48da87883f42f16e4ff7b8a48cae19f908bfa33b2a549479259n/aPhorpiex
2026-05-1512.exeexe aa261c4c46a0c4ab97d0c8b8f36341a688b8803f46f9da85008410a9a889c858n/aPhorpiex