URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/kliulij.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853309
URL: http://5.252.155.72/load/kliulij.exe
URL Status:flame Online (spreading malware for 1 day, 11 hours, 45 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:05:16 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe LummaStealer opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-27kliulij.exeexe 4c15644f4a1d25cfdacecd5618eb88637d994a031a8c6f8c772a5db01ada3080n/a ACRStealer
2026-05-26kliulij.exeexe 8f3add069ccd037e62de2db21914945ab025319a0719e3d5f5bc2df359383a71n/a
2026-05-26kliulij.exeexe b501ba0d14d6513412a1b98344c4f316cc50ac0b319226a624c48524b7a01a90n/aLummaStealer
2026-05-26kliulij.exeexe d353d849b0a656ad633b677bd3413c5da9975bfac34c90927b948ee1289f058cn/aACRStealer