URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/os1/VKkQj.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853310
URL: http://5.252.155.72/load/os1/VKkQj.exe
URL Status:Offline
Host: 5.252.155.72
Date added:2026-05-26 05:05:16 UTC
Last online:2026-06-04 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Takedown time:9 days, 0 hours, 42 minutes Bad (down since 2026-06-04 05:48:26 UTC)
Tags:ACRStealer exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-28VKkQj.exeexe 5588efb268c8bcc40cf1942db862387ccd2f4f8ca88464c0d316faedf90f80d5n/aACRStealer
2026-05-27VKkQj.exeexe e4c1e25cedf9e57278dea1aedf0aca02bfce47c2f97c0f57725f3c351bfb2374n/a ACRStealer
2026-05-27VKkQj.exeexe f010585162a905c486b5ddd0cdae3ad5ad232c94a6091ed718692c8f72b0b68an/a ACRStealer
2026-05-27VKkQj.exeexe 38cf89b07d7036ff09ead8bef8c22aa26949cb7863eeb3b02692ffa9ca954138n/a ACRStealer
2026-05-26VKkQj.exeexe 119b387e12f79637227c095822f018cc3cfb6e1111e0e473e6edadcbc08cf350n/aACRStealer
2026-05-26VKkQj.exeexe ef262340421fcb93d5f0c0d0bf418bc9fc6224398dda3093028ed8c97cc5bba7n/aACRStealer
2026-05-26VKkQj.exeexe 6b82cb8b9becd746aac0583fac20c3d5982e56b8ae5d39aa2ac60a5c80275d85n/aACRStealer
2026-05-26VKkQj.exeexe c577c6c87bd8a143598000e63d53c8e09b4f7d7a8b8c5de36f7479b5f4411274n/aACRStealer