http://165.154.125.212:8080/02.08.2022.exe
Classification: Malicious
http://165.154.125.212:8080/02.08.2022.exe is a malicious URL. Linked to Pay2Key malware. Reported by 2 threat sources, last seen 2025-11-27.
Current activity
- Offline — no longer resolving. Last online 2026-01-14 13:29:07.
- Malware distribution — This indicator is distributing malware.
MITRE ATT&CK associations
Malware families: PAY2KEY (S0556)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Pay2key | Maltiverse Threat Observatory | 2025-11-18 18:31:28 | 2025-11-27 12:31:47 | S0556 Pay2Key | |
| Malware Download | URLhaus Abuse.ch | 2025-11-18 16:34:15 | 2025-11-18 16:34:15 | malicious-activity |
Tags
censysURL information
- Direct IP
- 165.154.125.212 — this URL points straight to an IP address, a strong indicator of malicious use.
- SHA-256
1c9b6459d444d3e887734aec4cdc8196439ff6c2648a9681811e5ad0606aee80- First indexed
- 2025-11-19 07:48:26
- Last updated
- 2026-01-14 13:29:07
- Last online
- 2026-01-14 13:29:07