URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/bjbh.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853303
URL: http://5.252.155.72/load/bjbh.exe
URL Status:flame Online (spreading malware for 2 days, 7 hours, 50 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:05:15 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe LummaStealer opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-27bjbh.exeexe 86bc296e24a0dce418e4bbf01f1413301ffff6dc62d39871036be7b4438f1c44n/a ACRStealer
2026-05-27bjbh.exeexe e535cab50e8134087f804a818c9c96098e56520a27bb0b35c82de020937938b4n/a ACRStealer
2026-05-26bjbh.exeexe 5a7aa4215a980ff644e445fac5647e3e00c1c831b2850b57ad4a2b7c30317377n/a
2026-05-26bjbh.exeexe fa41d6b4e53c71633387a987d3bed687430e7a4e7b91e757e362fbbee7386e1fn/aLummaStealer
2026-05-26bjbh.exeexe 055950ef8db469b7f9264e1c651a125ce969677d7d86d3e31deb31b82b3958f0n/aACRStealer