URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/ojujn.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853311
URL: http://5.252.155.72/load/ojujn.exe
URL Status:flame Online (spreading malware for 1 day, 17 hours, 13 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:05:18 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe LummaStealer opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-27ojujn.exeexe 3b937e02a557993cb4c0919da1c01d5c00863dbe474a54744d126eb9f19e0b20n/a ACRStealer
2026-05-27ojujn.exeexe 76a51fb7d82bcdb120f3128172ec5682f630789b8b4aa9450dc65184ea3a15e6n/a ACRStealer
2026-05-26ojujn.exeexe ab9f6e17e46f95364f6704db5003993cbd384a5fd61f99ef9a0f10113dce6ab9n/a
2026-05-26ojujn.exeexe 040e0d767faccb2b706ec81553b14743f1d24f508c69bb5921716bdeb14ca1cbn/aLummaStealer
2026-05-26ojujn.exeexe 6871848bb724a184e393a734c9de9c17c41da1f26359755696f0df40685c42f2n/aACRStealer