URLhaus Database

You are currently viewing the URLhaus database entry for http://cloud55file.cc/load/kliulij.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3855075
URL: http://cloud55file.cc/load/kliulij.exe
URL Status:flame Online (spreading malware for 4 days, 5 hours, 52 minutes)
Host: cloud55file.cc
Date added:2026-05-29 06:33:21 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-05-29 07:36:14 UTC to abuse{at}intezio[dot]net)
Tags:ACRStealer exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-02kliulij.exeexe 895a5749240807cc90ee488930e25e305f02337af39b94dd97d9a9033f782cedn/a ACRStealer
2026-06-01kliulij.exeexe 7fb115a02e146a2b818ccd39748f15d93ac0b8e465db273a0dab15ef69b7bcbcn/a ACRStealer
2026-05-31kliulij.exeexe 8c3310d5575f4d73baabe2268f2da9bd3d87bd701225adc526185610a730b9c4n/a ACRStealer
2026-05-30kliulij.exeexe 1450d14c4de20a5f645b04d2cdea6a626315139c90b5d614cf5ef39adcb9904an/a ACRStealer
2026-05-29kliulij.exeexe ead52049a68c24e8538cd7763e59414f4b6561d458fab3bafd719543ce037025n/aACRStealer
2026-05-29kliulij.exeexe 8432d734b2af5ee148915399c6f5d63b3f3435ab612182ad53b0d8897fbf74c9n/aACRStealer