URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/kythy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853312
URL: http://5.252.155.72/load/kythy.exe
URL Status:flame Online (spreading malware for 1 day, 14 hours, 19 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:05:19 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:06:11 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe GhostPulse opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-27kythy.exeexe 94db5892d51fa7f24c6f406591d5cc143f48f3f9f576c66d36a8682e3950102bn/a GhostPulse
2026-05-26kythy.exeexe 828405d66881b770753d58349534c978672cda97591e8eb393beca734896539an/aACRStealer
2026-05-26kythy.exeexe 943cf1ebeb089abcd2e6ff0c2bfefa4631855948ab3ef3811cba1c635aa389d1n/a GhostPulse
2026-05-26kythy.exeexe 833bffd0ff2291001e0cb62f529cf947ba2753fa5888820848a2014eda2dc334n/a GhostPulse
2026-05-26kythy.exeexe d28c7e1fb7db6117c741cac2a5819385de3d1ee51fadc475c15536f5549b4cb2n/aGhostPulse