URLhaus Database

You are currently viewing the URLhaus database entry for http://5.252.155.72/load/hjbk.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3853315
URL: http://5.252.155.72/load/hjbk.exe
URL Status:flame Online (spreading malware for 1 day, 14 hours, 21 minutes)
Host: 5.252.155.72
Date added:2026-05-26 05:06:07 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-26 05:07:12 UTC to abuse{at}altawk[dot]com)
Tags:ACRStealer exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-27hjbk.exeexe f878ce4b42c28ce8ac4e965c550988c2f7ef753d4a39888f103c39f7e6222ba6n/a ACRStealer
2026-05-27hjbk.exeexe f251271a7492deec499dbe387d5b0500ef3fe2bb8f8b0d86940bac97c11f7345n/a ACRStealer
2026-05-26hjbk.exeexe 350a2b69e5de4c35dc2b9592e145ff425373356cb2fed475716e1bf7455dd802n/aACRStealer
2026-05-26hjbk.exeexe 90d54589bfae10deb74fa349668a5af649c546b8eddb75d5000174601920cf77n/aACRStealer
2026-05-26hjbk.exeexe d5655568fee9c610139d41d367afc74e768e1c8baf70e37912e9ebeb27b5d411n/aACRStealer