URLhaus Database

You are currently viewing the URLhaus database entry for http://185.215.113.209/plug/plugin1.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3338812
URL: http://185.215.113.209/plug/plugin1.dll
URL Status:Offline
Host: 185.215.113.209
Date added:2024-12-09 16:07:14 UTC
Last online:2025-04-28 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-09 16:08:13 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 19 days, 20 hours, 16 minutes Bad (down since 2025-04-28 12:24:29 UTC)
Tags:dll

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-15n/aunknown 46c315384fdd9b730049e4ebaacdaea104170d718ff3d1538650d9b2cf50f878Virustotal results 14.52% 
2025-02-17n/aunknown ad1fd02720b87e2e5937f92315b8eb34266793898f9e987583bb02e7f9343bc5n/a 
2025-01-25n/aunknown 4bcc6de782d520eb740316d7afc492ffa5effce2341673c41022927248ec11bdn/a 
2024-12-11n/aunknown 3739fb1ff7f5dec4fa57fb64a4bbce3396eb5a7d7728b90f2aa7e481d53b55dbn/a 
2024-12-09n/aunknown 56212226aa1d904c9dafc2aef424eae6ff104cb8cff1b3a1f2f2aa96cd21642cn/a