URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/jhgkuyyg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853299
URL: http://5.252.155.72/load/jhgkuyyg.exe
URL Status:flame Online (spreading malware for 25 days, 12 hours, 39 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:05:14 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe LummaStealer opendir RemusStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-20jhgkuyyg.exeexe cef76c2d39974206a4792d0ac7a58f4a3b7b1073ef4588cdf38a88bea50cb111n/a RemusStealer
2026-06-20jhgkuyyg.exeexe 7abbb96044bdce043a472655ffa70755f98c591b0fa4743386f594e0cc007dden/a RemusStealer
2026-06-19jhgkuyyg.exeexe c1d067c076f8d0d818aca72cefa32df501a6a887d96e407bdfe08d712b6ff781n/a LummaStealer
2026-06-19jhgkuyyg.exeexe 18768e002f6f953ad6b9f3265d6e438ec19d0ffa05afaf28a72a04417c35528cn/a LummaStealer
2026-06-18jhgkuyyg.exeexe 97e7c5a99fc8a7a2e593dc2fc070df8dbc54b704ce2096982d15e7aaa951c48fn/aACRStealer
2026-06-17jhgkuyyg.exeexe 59b0260257ba3292232927eec17e5732bc65456a871b5aeddb8ede56eb85eed7n/a
2026-06-17jhgkuyyg.exeexe 563355f7e87ac06181c5338b6adfaa77cddeb1eeab2141e1a1368ac4d7464f53n/a RemusStealer
2026-06-16jhgkuyyg.exeexe 81fb05b567678262a92f21f177a3cbca186457be4728c99980b342a016842c3an/a RemusStealer
2026-06-14jhgkuyyg.exeexe e6348cec8de4916984e053bb72670122d2b339f7355f73d7e4e9f58c1b2cb15bn/a RemusStealer
2026-06-13jhgkuyyg.exeexe 419fa3a918a688389b7be61f3c5ebcffe35e812ce2ee42196f2955f9016aa9c7n/a RemusStealer
2026-06-12jhgkuyyg.exeexe 3c044fc233e0a772c2f7af3994b07516ae8ea92838013ffed856c42693d1ebfdn/a ACRStealer
2026-06-11jhgkuyyg.exeexe 3cb787814f38298ad82b7d2ad326a53cfa489a4ede70f00406333a4e08f19a06n/a ACRStealer
2026-06-10jhgkuyyg.exeexe 574a9dc8d3c70754407618fba81e49af5229a673a7dc9a194f11cd877af1683cn/aACRStealer
2026-06-09jhgkuyyg.exeexe 87053c64d489ffa6a3754cf44641980e13a5acd515e9c2b5c269c8018016495fn/aACRStealer
2026-06-08jhgkuyyg.exeexe 081efc68d0ab8a9885d3b5187a4f6774d286f5397d30563e68f10875b56d1bc9n/a ACRStealer
2026-06-07jhgkuyyg.exeexe 2c100dec3a533688ed850cf6438a622d439cb4263e816110802c901be2de2bb0n/a 
2026-06-06jhgkuyyg.exeexe b18cf2363beececc54c71a78363f90a03e24dd4f75ab54bc84df3b53e5c488a5n/a ACRStealer
2026-06-06jhgkuyyg.exeexe f1c585d6caae780811528f0041586f712a1d303860fd29aaf33714c9b2cebc13n/a ACRStealer
2026-06-05jhgkuyyg.exeexe cbedd93651d45388c2e59d79959d26cc14232a159edb45f61d1db02e8b9c6815n/aACRStealer
2026-06-04jhgkuyyg.exeexe 16a8f92653ea8838ce2fa376cae48f3f448e7ac95758afa23c0ac1e808a78f89n/a ACRStealer
2026-06-03jhgkuyyg.exeexe e39d19a4e56388b252e757732a65033f7a416dd2b0ad263cf4ccb84a0edadd44n/a ACRStealer
2026-06-02jhgkuyyg.exeexe dca95750a25a38b562dd4867c9cccd917852156099d312d3fcb271956677a3f1n/a ACRStealer
2026-06-01jhgkuyyg.exeexe 526c8e73711b03ea7ff048f707ee41eaa7b476e3a6fa26d7c095afa41b93e54bn/a ACRStealer
2026-05-31jhgkuyyg.exeexe 4681dafe8e18721543e1c6bea9f7383e6dee8d55da7068a43d7916cc6aa4602en/a ACRStealer
2026-05-30jhgkuyyg.exeexe 53ec8d39e878a03727cc2de707ee5a756bac9b48a2baa634b2f2d84e029b38d8n/a ACRStealer
2026-05-29jhgkuyyg.exeexe e0ad30d3587be86f17733492d4b774601356ff5b5e09c17f536704a4ced88f9en/aACRStealer
2026-05-29jhgkuyyg.exeexe d18331e036ccd1a2e09917bfcda13b4a6f60e8e294a9a2c5624110e777175d51n/a ACRStealer
2026-05-28jhgkuyyg.exeexe bd7832157bc4ccff2632e3e457d47042fddd8327a72549f1dda6bb822c85f04fn/aACRStealer
2026-05-27jhgkuyyg.exeexe bf341f23a75361a2e24a5c42e8b345a3e29cf0b35d4fccf9376c68108b1febdfn/a ACRStealer
2026-05-27jhgkuyyg.exeexe 8f454dc17a40b766bd1cb6beaf50330ddbc89450a11149d1648a79329e393fe8n/a ACRStealer
2026-05-26jhgkuyyg.exeexe b0bc17dda19e36d395e354f6a861e93a70780029bb35116ea3616e316c588710n/aACRStealer
2026-05-26jhgkuyyg.exeexe 7620884e50fd7741417ecdb81b41f7c7d9452b89d6905a837ad30a7bc8dc9969n/aACRStealer
2026-05-26jhgkuyyg.exeexe 624f52cc31cd7ae5a311c9800b619386c9fd1a45af11b4e852391699ce36d3d8n/aACRStealer