URLhaus Database

You are currently viewing the URLhaus database entry for http://165.154.184.75/NEW/plugin2.plg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3461771
URL: http://165.154.184.75/NEW/plugin2.plg
URL Status:flame Online (spreading malware for 1 year, 3 month, 2 days, 9 hours, 33 minutes)
Host: 165.154.184.75
Date added:2025-03-01 08:58:47 UTC
Threat:Malware download Malware download
Reporter: skocherhan
Abuse complaint sent (?): Yes (2025-03-01 08:59:07 UTC to hegui{at}ucloud[dot]cn)
Tags:opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-31plugin2.plgunknown 7769dd7ee751fc93f926b69a744c5bbb866406072b474f4027726f6c03ceaa42n/a 
2025-05-09plugin2.plgunknown 8cbfc4e77a04cc17aa975ad7c180f28b9a9f2bac9998df990258b659b4c3dea7n/a 
2025-03-25n/aunknown 1d74e0d1befa5f9b11ce881798c5e66a4d18c7dff934b7b33a6aed901aac8664n/a 
2025-03-01n/aunknown 4c5f52ebbc377c051322d5d2cd24eaa377787f94bbbd33323486124684ab5adan/a