URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/os1/VKkQj.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853310
URL: http://5.252.155.72/load/os1/VKkQj.exe
URL Status:flame Online (spreading malware for 1 day, 13 hours, 25 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:05:16 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-27VKkQj.exeexe f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68an/a ACRStealer
2026-05-27VKkQj.exeexe 38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138n/a ACRStealer
2026-05-26VKkQj.exeexe 119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350n/aACRStealer
2026-05-26VKkQj.exeexe ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7n/aACRStealer
2026-05-26VKkQj.exeexe 6b82cb8b9becd746aac0583fac20c3d5982e56b8ae5d39aa2ac60a5c80275d85n/aACRStealer
2026-05-26VKkQj.exeexe c577c6c87bd8a143598000e63d53c8e09b4f7d7a8b8c5de36f7479b5f4411274n/aACRStealer