URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/os1/uRgOy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853302
URL: http://5.252.155.72/load/os1/uRgOy.exe
URL Status:flame Online (spreading malware for 1 day, 10 hours, 57 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:05:15 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe LummaStealer opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-26uRgOy.exeexe 071ea680902d561e0581c9c370f98634aa9edcc9882e4624abc739ebc223df43n/a
2026-05-26uRgOy.exeexe 5d5e38f5e20612dbadfd68c291b11d0afb78566b0df1b3ed798163a3c0309940n/a
2026-05-26uRgOy.exeexe 7b74bea75be45d0a798732cdb54674811c207a3b118960c2146e9e97fb35c94bn/aLummaStealer
2026-05-26uRgOy.exeexe f93d8d79ae62c9864e53e5abf92f5c905c358b6ac397c69418765a303947c1d1n/aACRStealer