URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/kliulij.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853309
URL: http://5.252.155.72/load/kliulij.exe
URL Status:Offline
Host: 5.252.155.72
Date added:2026-05-26 05:05:16 UTC
Last online:2026-06-24 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Takedown time:28 days, 19 hours, 21 minutes Bad (down since 2026-06-24 00:27:35 UTC)
Tags:ACRStealer exe LummaStealer opendir RemusStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-23kliulij.exeexe 4a405c754f4797656b6c4ca1f6f2eeabbe6736b5deac36b223e0086d7cc1da7fn/a RemusStealer
2026-06-22kliulij.exeexe ddadc2a3cf060e35ff9b570052116053aac6a98a8ad6587b98ec95e14fcff489n/a RemusStealer
2026-06-21kliulij.exeexe 0104efd8d72ce5de02b3f32aecf154ffa1f616be7aeb58552a80f7b650b291cfn/a RemusStealer
2026-06-20kliulij.exeexe e47519f1027a8e705eea076a3cc51ab792a50286ef0d7e5cdf9df297e3d9a7a9n/a RemusStealer
2026-06-20kliulij.exeexe 72e4e0f4f7390e555abf5950fb26f7769a007c6321d6728e1b44bdbe89c09f3en/a RemusStealer
2026-06-19kliulij.exeexe 817ac7a4ee5b546a812b129c9b9cfbb4581988bd95ac3e2a32a83b82f1bf430cn/a LummaStealer
2026-06-19kliulij.exeexe 89c66cb60337dd2f0901bed8919fe22ad88ae1874e92977cba2f9b37cf79dd5an/a LummaStealer
2026-06-18kliulij.exeexe a1bcb598e7f10fb7c944527e5970d8380fb106d2a8a61ee929d4c99fde17d1a4n/a
2026-06-17kliulij.exeexe 14dc16160c3525caee94a3f2c74f00511c974bde67723db3df936936a0101919n/a
2026-06-17kliulij.exeexe a44ec3a4e3c5a2076d2bcf75bebd01f2e596bdca44dbfec85ebfb933b7a8d865n/a RemusStealer
2026-06-16kliulij.exeexe 9a883112f76b4a0d141ed911d33b0d9fd4e3e01c6fea00859716bc7c103c8aa8n/a RemusStealer
2026-06-16kliulij.exeexe 51f8140f3d2d6915cc5156849a7d62ff1bc1bb6dfbb29934f4983a5afd08fe09n/a RemusStealer
2026-06-14kliulij.exeexe ef0c8c65f60f47b3ec347f4dec553c6a1781d3c8c51210507b5a291671e2184dn/a RemusStealer
2026-06-13kliulij.exeexe 7c98950ce2ec028b5d653e699ca4cb12b09aa84a732be3a8ae9321378cfa5c67n/a RemusStealer
2026-06-13kliulij.exeexe 9132e1cbb7ff93b6a816748dee57ca3600e7ab490b9ff56dcd8d70eb6800a006n/a ACRStealer
2026-06-12kliulij.exeexe f052abe9d1887b2b415db683be36a0deb9f879e907845eef09a52978a9582a1fn/a ACRStealer
2026-06-11kliulij.exeexe c4e5978e746aac34d8bccdc1e6311e98071a244fd88b3a1a7dc278b0ab2452b7n/a ACRStealer
2026-06-10kliulij.exeexe 203f770e4bbab0219689d78aed3a89fe9798e183b0fddf61adbc7251293298cen/a ACRStealer
2026-06-09kliulij.exeexe 15054ba40150acc0ee8ffe9a13a5681965e87b2e827e213444ae2d9cce1bb38bn/aACRStealer
2026-06-08kliulij.exeexe 907e19895f1f5a8da79f42514cc611b460c4525747ba472ce524b196ebde0527n/a ACRStealer
2026-06-07kliulij.exeexe a8ea36139921e41e59284a31ababfd54cbfaf6d31fb51820bd64991b62d7f372n/a 
2026-06-06kliulij.exeexe c9ad64a8b3a366540c3e0bcc49ee09032d3f1b4eb92aa20c7bc1c1322991c0a7n/a ACRStealer
2026-06-06kliulij.exeexe 11eda903a8f69c27d910b58a3361d31cc83e82540fa95e7f84bb30f9efc8bccdn/a ACRStealer
2026-06-05kliulij.exeexe 6b9dd9562c04297552e8888d34517bf89c8739b4a1897961204145271ba86830n/aACRStealer
2026-06-04kliulij.exeexe 43d4d2c2521bce7ea2e52107c17f017c39d2d3f0bc6cfb630f662da6b08bd822n/a ACRStealer
2026-06-03kliulij.exeexe cb1080778b37fcb5365db4ee88dc623de331c13b95f88bc75a11785ddc61b80fn/a ACRStealer
2026-06-02kliulij.exeexe 895a5749240807cc90ee488930e25e305f02337af39b94dd97d9a9033f782cedn/a ACRStealer
2026-06-01kliulij.exeexe 7fb115a02e146a2b818ccd39748f15d93ac0b8e465db273a0dab15ef69b7bcbcn/a ACRStealer
2026-05-31kliulij.exeexe 8c3310d5575f4d73baabe2268f2da9bd3d87bd701225adc526185610a730b9c4n/a ACRStealer
2026-05-30kliulij.exeexe 1450d14c4de20a5f645b04d2cdea6a626315139c90b5d614cf5ef39adcb9904an/a ACRStealer
2026-05-29kliulij.exeexe ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025n/aACRStealer
2026-05-29kliulij.exeexe 8432d734b2af5ee148915399c6f5d63b3f3435ab612182ad53b0d8897fbf74c9n/aACRStealer
2026-05-28kliulij.exeexe 1cf857a9b341295ce170abd7d79f66e1d2026adc39927e97a658a1af097e52c1n/aACRStealer
2026-05-27kliulij.exeexe 817c988b8b71304b6763de3a86630d00d99dea68bc1a6f80e9261d2bca39ac40n/a ACRStealer
2026-05-27kliulij.exeexe 4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080n/a ACRStealer
2026-05-26kliulij.exeexe 8f3add069ccd037e62de2db21914945ab025319a0719e3d5f5bc2df359383a71n/a
2026-05-26kliulij.exeexe b501ba0d14d6513412a1b98344c4f316cc50ac0b319226a624c48524b7a01a90n/aLummaStealer
2026-05-26kliulij.exeexe d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058cn/aACRStealer