MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09c4641feea6d8c09f8a9b7b13819172820ef08653758cc14bb2e7fafbf86cc3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 09c4641feea6d8c09f8a9b7b13819172820ef08653758cc14bb2e7fafbf86cc3
SHA3-384 hash: 565327566bcfbe4c4f54c50abb2dbc9266a5aee831f2b5581d1dd7cd9b31bf750094d1a68d4d71c8251371f9a4d43da0
SHA1 hash: e01d6058b54cb904d196389cd282df261d9e4a75
MD5 hash: 785152ec840e679381f94fefdd5b27f7
humanhash: undress-mars-monkey-fix
File name:𝓢𝓮𝓽𝓾𝓹 🜸 𝓟𝓻𝓮𝓶𝓲𝓾𝓶 🜸 𝓓𝓸𝔀𝓷𝓵𝓸𝓪𝓭 🜸.7z
Download: download sample
Signature ACRStealer
File size:14'266'844 bytes
First seen:2025-11-23 16:05:28 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
Note:This file is a password protected archive. The password is: 2025
ssdeep 393216:olF4my9gBGW9nOfdVbjzzk6FAvyBOGDu9kZr0Z/AFbO:oT/UcOXnk6FEyMFkt0B
TLSH T10DE6330B7AD9F60F5B387D00BE38DE31D6E53EB700E16AA78EB9C005526BD05941AF46
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:46-62-234-82 7z ACRStealer HIjackLoader IDATLoader pw-2025


Avatar
iamaachum
https://downtoherq.click/ => https://mega.nz/file/CUlHmaBb#XsOTw-dMo-I4IxXvfLh8zmIfN-OvJzHX7R0BLEAy9RY

ACRStealer C2: 46.62.234.82

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
ES ES
File Archive Information

This file archive contains 129 file(s), sorted by their relevance:

File name:Microsoft.WindowsAzure.Storage.dll
File size:1'199'184 bytes
SHA256 hash: 1577b2b1838610d4cb337f5874f921d48af5c05bf56db4af03342cf659d807ab
MD5 hash: 21a9458eae60d43ef8b05dc4da297ef4
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.AspNetCore.Mvc.TagHelpers.dll
File size:284'952 bytes
SHA256 hash: 7f8015d155c0c5ca7df3b81de0a327c38d263d9906ef996fc2fc4a39e0095e3c
MD5 hash: 2c039c0e106ed0fb9f19df4ac29f371f
MIME type:application/x-dosexec
Signature ACRStealer
File name:Setup.exe
File size:1'092'704 bytes
SHA256 hash: 9e3cbb6154c2e0c1877b2914bc5ed4b3adc0023efb43332ff2dad9d4abaf7d7f
MD5 hash: d0bf19ac57b6d259f9ec739c6e717beb
MIME type:application/x-dosexec
Signature ACRStealer
File name:kdestroy.exe
File size:18'512 bytes
SHA256 hash: 4dd223b8183d02dd6eb192246d3e6537fe979aef287ee8304234b42c41a0c39a
MD5 hash: 9d523afce92133207a7cb707ed0980f1
MIME type:application/x-dosexec
Signature ACRStealer
File name:FORM.DLL
File size:239'488 bytes
SHA256 hash: d4ec2f925b723a30e70aceb080c19228c8e2c128daaee33955af9700451ac2c6
MD5 hash: c0f7d8b2cdf87a84854c766cf46478c1
MIME type:application/x-dosexec
Signature ACRStealer
File name:MSVCP140.dll
File size:447'568 bytes
SHA256 hash: 654412a50c83d218d9f72f8bbd0e0d2963ed0b58be59d6661e931f32dc9f80d8
MD5 hash: 05f1b8a11885aa248408597f25ee9d47
MIME type:application/x-dosexec
Signature ACRStealer
File name:final_const12.phpt
File size:298 bytes
SHA256 hash: 363ba9b3eeca1b4d54deb8e46f7e72e9f0b8a6bd6e5cd4885c7000c446950f80
MD5 hash: f754eb304428b2fde60889341c3d8142
MIME type:text/plain
Signature ACRStealer
File name:libts_plugin.dll
File size:623'744 bytes
SHA256 hash: 723100a343b4526b2d543324f0057822c83422580c2e3c804ba42ab34350c4bf
MD5 hash: bf9c88f2d880f0ba4fbc2f1d7868c7a0
MIME type:application/x-dosexec
Signature ACRStealer
File name:Matrix.dll
File size:1'166'848 bytes
SHA256 hash: f6a2c0b74821bd7ce900f60ad5cfe0c1809997dbe1c982b6fef5c2289bc0e515
MD5 hash: c774fbd23c7c5b40bc7c296f13ac795f
MIME type:application/x-dosexec
Signature ACRStealer
File name:bug_aaa.phpt
File size:769 bytes
SHA256 hash: 5589cd89375d19422632b8fab196b2191cbe4c2c450c81f037106079d34011ad
MD5 hash: c283ebc3455fe4840d56c5467972b784
MIME type:text/x-ruby
Signature ACRStealer
File name:config.w32
File size:1'616 bytes
SHA256 hash: 81b9cd4f95f6c9140fbe5a5e78a527ee1320ea68524a419233c1b6e7161b3f1f
MD5 hash: 2416626aa9b9bf85c4b42e3271409f07
MIME type:text/plain
Signature ACRStealer
File name:htmlentities-utf-3.phpt
File size:2'627 bytes
SHA256 hash: d666688d57c97976b33b89cf581f1f2bf2b1eada699e13dbd00bde714cddf734
MD5 hash: 056036de81e7f4d4c06daf84eb111f56
MIME type:text/plain
Signature ACRStealer
File name:DateTime_wakeup_exception.phpt
File size:1'498 bytes
SHA256 hash: 8ef743033a54c1db0d56e93ff688196fe6ad1043cc4f282fe122cd02b1129279
MD5 hash: a5ecf66909affbad29136fad7a4fa5b5
MIME type:text/plain
Signature ACRStealer
File name:INTERFACE_BUILD_PROPERTY.txt
File size:835 bytes
SHA256 hash: ee0a457c182fd84e24f953ac0a69d1a45922727aeb2c810fc3e59edaeb445bb2
MD5 hash: 6bfe41f21ada00c239efef6a370d3823
MIME type:text/plain
Signature ACRStealer
File name:r4_groupH_simple_rpcenc_010w.phpt
File size:2'218 bytes
SHA256 hash: 4f19f3263993074942f335e6f5b8a61924fc5a2848cf16c938ea2045c59d2581
MD5 hash: 2b3cd323307eae260269151233290096
MIME type:text/plain
Signature ACRStealer
File name:bug69485.phpt
File size:292 bytes
SHA256 hash: 6deb316229fb520a7f8c9fb35c4d11a84444817ed784985bc29f9567d8054c0f
MD5 hash: 81e6ccbd15da93a76eac423ec5b16abb
MIME type:text/x-c++
Signature ACRStealer
File name:System.Web.Extensions.Design.dll
File size:335'872 bytes
SHA256 hash: 75333bfea7ac225d90a18f91f0ee9654434b67147ea064f0d308b82596ef1f83
MD5 hash: c9ab040176a7dbd8c57ed08eeac4057f
MIME type:application/x-dosexec
Signature ACRStealer
File name:rename_variation5.phpt
File size:2'556 bytes
SHA256 hash: 7fa44f125f44a16d2226308c39ebf0a1b1219927306ccf769b67efc701254921
MD5 hash: 7b050647f42825741abb79339d09df2b
MIME type:text/plain
Signature ACRStealer
File name:tt.txt
File size:14'202 bytes
SHA256 hash: 18479d66e0c8b5144ea32cc9d6b58eb8748e80d2c3bdec0dbd99bbc3ab42495d
MD5 hash: 6e299b81edacf15face1271d032cc5a0
MIME type:text/plain
Signature ACRStealer
File name:OFFOWCI.DLL
File size:529'280 bytes
SHA256 hash: e6718e795ea9e3424502483ee7f38c8d1ef362bcf0caa0e25ecdd202604b6722
MD5 hash: d40944f6f483ed5b4cf5142ede922908
MIME type:application/x-dosexec
Signature ACRStealer
File name:mc_demux_mp2.dll
File size:810'696 bytes
SHA256 hash: 0fee618a230f10cafdbcba1c2181c36f33bbe2539b5191cad82e510896daae43
MD5 hash: e08292ce02d82ce0d32adeb7762fa56f
MIME type:application/x-dosexec
Signature ACRStealer
File name:build_single_error.txt
File size:267 bytes
SHA256 hash: 339f15720108a59e00466152d7b29c2f82877c917872283261b4506f56e7e255
MD5 hash: 35a0610913d7fd669e00e3e25bf0bc71
MIME type:text/plain
Signature ACRStealer
File name:example.com_retract_self_pseudo_v1.0.0-bad.txt
File size:196 bytes
SHA256 hash: 46758c24a510c524f1bbac5b51225c93cb8f721e284aa636fd00d259d9ccdf22
MD5 hash: c6653399e6931296a135974006836c03
MIME type:text/plain
Signature ACRStealer
File name:ImBatchContextMenuHandler.dll
File size:392'704 bytes
SHA256 hash: d58798f3b423e38b352e0a92a266b399a3bb5a9a141a73699223bb5d04b55924
MD5 hash: 70ab1788bc402cc6eca8235f5e612023
MIME type:application/x-dosexec
Signature ACRStealer
File name:TMRegEx64.dll
File size:822'288 bytes
SHA256 hash: eab6419cd005e8a1ed4757cbb8d787036e61fa43e6555cb2689f3716054c1c04
MD5 hash: 75e94d3ca12a7b80d5779302bad90495
MIME type:application/x-dosexec
Signature ACRStealer
File name:std_vendor.txt
File size:975 bytes
SHA256 hash: 0a93fef7c02b9cd8c31ced0af350c296b39cff67d2f94f523d906c80499e844b
MD5 hash: ee173de84aab38a5cbb4494d0bc0e135
MIME type:text/plain
Signature ACRStealer
File name:VariantClear.dll
File size:594'872 bytes
SHA256 hash: 9cbf2817134cfe02ba1b337ea1b47cac2feedfab66750be553a4cffb17100395
MD5 hash: 3589df80891d2fadbf2c59aa8b3df772
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.CodeAnalysis.VisualBasic.Workspaces.dll
File size:822'960 bytes
SHA256 hash: 03e11c6686f9e1a0f7493c14fcdf5807b353d48952ba548f60a41032a55c2430
MD5 hash: 481ecd72276c9d9bd7d6e6a6e2a81696
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.VisualStudio.Platform.SearchProviders.dll
File size:208'416 bytes
SHA256 hash: b34682b34cb21e17b37a706c1a68f18587cf887088dd08489e3abd2a4868525d
MD5 hash: 93b1bcce719eefd98d6a389b1d58d693
MIME type:application/x-dosexec
Signature ACRStealer
File name:WinPixTimingCapturer.dll
File size:407'304 bytes
SHA256 hash: 7cc006c014c50f7f44bad4d831cb3119cd11500c6b947c35b69810841e4bea4c
MD5 hash: 5654ddda05d6bc8faa4a41fa722ab3d2
MIME type:application/x-dosexec
Signature ACRStealer
File name:help.es.txt
File size:7'632 bytes
SHA256 hash: db9a70fce6bed52532b856323f4d4a6a47b7def90f83d145e5757c2ebf2c36ad
MD5 hash: aa04475c3579b70cd782933202b57a11
MIME type:text/plain
Signature ACRStealer
File name:chmod_variation2-win32-mb.phpt
File size:1'815 bytes
SHA256 hash: d849e8362072d04eb707a72399b5f4fccf9bc625c4d56faea84ab8fd78f7c1b6
MD5 hash: cb17e8d74bf19890df5fd5661ab3aa6b
MIME type:text/plain
Signature ACRStealer
File name:DisplayLanguageNames.sk.txt
File size:33'492 bytes
SHA256 hash: f7a0b512fed80c2aecbf577d9399abb557eecb0599408d8cd1ac039ece8462a9
MD5 hash: f2990f568800b0a8e7eba88a00311a54
MIME type:text/plain
Signature ACRStealer
File name:MacCyrillic.txt
File size:13'353 bytes
SHA256 hash: a915d23b499d8d94d6e1ad2dbdcca06e1a5c4f36ffa37e7152b4591f1cb074f8
MD5 hash: 87e3bb393d087bdc8057e33be6f366dd
MIME type:text/plain
Signature ACRStealer
File name:Qt5Widgets.dll
File size:4'595'832 bytes
SHA256 hash: 4a12866260ff266eeffe0b4d8eaf27ed064682f00e8907bd53956f446e23c496
MD5 hash: eb4aea9ff7c75da2a4925e83f8defe3e
MIME type:application/x-dosexec
Signature ACRStealer
File name:vstest.console.dll
File size:645'400 bytes
SHA256 hash: f4f91b07398054ceb136e1a89f3ec7995eac10a5c58ee16daa549e55c2f13ba6
MD5 hash: fb2971ce594f75700c556a44bc9bbca7
MIME type:application/x-dosexec
Signature ACRStealer
File name:bug68370.phpt
File size:315 bytes
SHA256 hash: a67036ed4bc8b307432477277a1c2e51017742256a966fe9b2c102d57d1b96ab
MD5 hash: 28c3a71e6d79304c4f7599cebbd0ae38
MIME type:text/x-c++
Signature ACRStealer
File name:DisplayLanguageNames.is_IS.txt
File size:29'022 bytes
SHA256 hash: c84b471049a1a574c6796b3b1fa71931722d7da1902607d950a666e8d1e8ab88
MD5 hash: 61390ea35c2720b69b3bf6948fe70a0d
MIME type:text/plain
Signature ACRStealer
File name:StreamJsonRpc.dll
File size:912'288 bytes
SHA256 hash: 07f3b83c58f6d5df7c317e23d7c3e275b8593c11e9f463cafa1b6bb37359e06b
MD5 hash: caa48b672d23e71e6519f999ffea1262
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.DiagnosticsHub.Runtime.dll
File size:641'456 bytes
SHA256 hash: 0bc33f95abe15f5bdd2497ad4d6a2e41842fb84cfbb4e88fed695a7ee52afa5b
MD5 hash: e6fd280fe26d6dd5b951adc3b4b79aae
MIME type:application/x-dosexec
Signature ACRStealer
File name:vdt80p.dll
File size:841'096 bytes
SHA256 hash: a7ec764c38d6b7b63b3c3232aab814965c04ed56ab31aa7f938ded1c563086cb
MD5 hash: 82eb29d006b4b3c67de984051dbd8a4e
MIME type:application/x-dosexec
Signature ACRStealer
File name:bug80384.phpt
File size:664 bytes
SHA256 hash: ce1df8ea4982a5270bbe349ee91a22402eec0357b45e3ccd7a82ed675d1d6e3a
MD5 hash: 9b181ed6ab4a6247c0340b1f3178edb5
MIME type:text/plain
Signature ACRStealer
File name:PluginSupport.dll
File size:404'168 bytes
SHA256 hash: 38146c0e854539d0c14beae21871b54adc0cc010be8de15e091137fa296da79c
MD5 hash: 6dc43a4e2d4a2572a47c806d1987e4df
MIME type:application/x-dosexec
Signature ACRStealer
File name:mod_retract_rationale.txt
File size:3'296 bytes
SHA256 hash: 0398babbb31f72b61259f5b3ee5b04b399fb1c7c270f7ae7cdb64bc2244f762b
MD5 hash: 037b536db52c0593f1e733d947944615
MIME type:text/plain
Signature ACRStealer
File name:uconverter___construct_error.phpt
File size:315 bytes
SHA256 hash: 0bbd13824a7e1302ab66ecdbf6e9e30dd3b9e5c5d96ab2e9a2f2f42b9dac4ede
MD5 hash: c9b58fc860b84c869e1f388423658298
MIME type:text/plain
Signature ACRStealer
File name:Qt5Network.dll
File size:1'115'256 bytes
SHA256 hash: 9c47b92c3fa1e29b4f205d3b3bb12ba47d48a3214147199c4e861ce54c4afb54
MD5 hash: e8308a75e58cf01a338ac206e406c9b0
MIME type:application/x-dosexec
Signature ACRStealer
File name:Qt5LabsTemplates.dll
File size:497'552 bytes
SHA256 hash: 4a97886e4c90de9b8eae030bef8492acfd6d38ed88dbd56e0268444bc0ec318f
MD5 hash: 9af554f4d47afcc7288ca839492aa7bb
MIME type:application/x-dosexec
Signature ACRStealer
File name:ku.txt
File size:5'841 bytes
SHA256 hash: a00b21a87a58adeff29ea379160b6ae72df5ec380f6e4c6a1bc352b6581fb4c4
MD5 hash: 6e9a3e86335c08c15350ba91df969269
MIME type:text/plain
Signature ACRStealer
File name:vet_flags.txt
File size:2'843 bytes
SHA256 hash: 4db03ef8a87024f0020768fef7274313be3fe613c28d570ec727f5ae10422ee6
MD5 hash: 4a5b341156af518905cbb742f0627a75
MIME type:text/plain
Signature ACRStealer
File name:System.Net.Requests.dll
File size:358'680 bytes
SHA256 hash: f268e1df93e5d8dbc88b63e71fce212e2b012cbf1ebe09f17aecf8491e73bc80
MD5 hash: 2da31d67be14afde43bae4e8c913bd02
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Diagnostics.Tracing.dll
File size:34'632 bytes
SHA256 hash: bce817c9d564e158ed4527b42bbd018758b56a2245882bd9ac0246c612eadffa
MD5 hash: d873afca6a1af005504ee5535d1ead5b
MIME type:application/x-dosexec
Signature ACRStealer
File name:stream_verify_peer_name_003.phpt
File size:2'071 bytes
SHA256 hash: d60b6bd288d934b35da1db211daec4c951e9581c0e33a7c48518b7936858b907
MD5 hash: 23aebbea88c586b40737a55742757324
MIME type:text/plain
Signature ACRStealer
File name:jump_mips64_n64_elf_gas.S
File size:4'534 bytes
SHA256 hash: faaf2c1c995d082a9d8d69b9719c1f26402c9f6c1a1ad6973de4ca31b17b5e0b
MD5 hash: eceef082525b4408d9eedae9a3941e63
MIME type:text/x-asm
Signature ACRStealer
File name:schema001.phpt
File size:809 bytes
SHA256 hash: cc4109f8ff10832a5f64689298be6bc40af33ed0d7b7c1f9092d7525e75d4a51
MD5 hash: cd648ae2a53b3004dbf92fc209b3b28b
MIME type:text/plain
Signature ACRStealer
File name:mobile_backup_status_server.exe
File size:2'190'288 bytes
SHA256 hash: 2401a5b0628966e482ea1c9cc0725503338b6e63a599b1d7b8b086c63f864b4e
MD5 hash: ca105eedb86f76fbcd1e65d7fc7bbf18
MIME type:application/x-dosexec
Signature ACRStealer
File name:Qt5Multimedia.dll
File size:746'480 bytes
SHA256 hash: 1a59ae2a9ff768ad6bfb888fe3dd2544e238f0b28da83cf375ebd803ce713dc4
MD5 hash: 01df79071f9da0b9b7bda3db7fdc8809
MIME type:application/x-dosexec
Signature ACRStealer
File name:mod_std_vendor.txt
File size:1'891 bytes
SHA256 hash: 06324cfda46c2fb4d28bf6229d01a07493b3c399edc4c10b4d2b856872fdff6e
MD5 hash: 61027c44428a4ed6f13f57c19ac90bf2
MIME type:text/plain
Signature ACRStealer
File name:ReflectionClass_hasProperty_002.phpt
File size:407 bytes
SHA256 hash: d51cb61edbf20f4047b41d416a2079f79b9e6f671a00744a934dfefc9933efd1
MD5 hash: c48e3ffb165541f31b2538410430526b
MIME type:text/x-c++
Signature ACRStealer
File name:language015.phpt
File size:344 bytes
SHA256 hash: f2ce2c7385d655ec5f94a084ad2bce17d46576f2efc47b9408a4abd62923619b
MD5 hash: d5601477802282059b4b588a5f837565
MIME type:text/x-c++
Signature ACRStealer
File name:System.ServiceModel.Web.dll
File size:491'520 bytes
SHA256 hash: 11bb9d7332fb5361c4ac7f6612873bc94da2c3acf48d8a93d8179d73fa0e707e
MD5 hash: eb71d8ba2569188c1a57519392c7b68a
MIME type:application/x-dosexec
Signature ACRStealer
File name:asort_variation11.phpt
File size:3'091 bytes
SHA256 hash: ff101832ed76996c2c7b9b79b2c5dd915dce434f64d4931c8ccb266283da1cca
MD5 hash: df67d332ef111aacae3c48385c3054ff
MIME type:text/plain
Signature ACRStealer
File name:version_buildvcs_bzr.txt
File size:2'743 bytes
SHA256 hash: e7af0cafe419018e92e10d747b9ea6bd18487c9c16ef15f301caec877be93cfb
MD5 hash: b21c55c8b8048fd89e7e59c3be0b2dd1
MIME type:text/x-c
Signature ACRStealer
File name:mod_get_newcycle.txt
File size:448 bytes
SHA256 hash: 2581ca533a2072301fbfb8493f9ad74531fa715123f0c051181eaaaf2803ecd6
MD5 hash: fb1cd3c35c2e4ce3e7d2d418962d32be
MIME type:text/plain
Signature ACRStealer
File name:calendar_getXMaximum_basic.phpt
File size:866 bytes
SHA256 hash: d0174365fc05892874d76bffa88e61b6a9940fac6516e0614acb64a3d93a6b40
MD5 hash: aa6845c0285ff14ad7c75a87417a88ec
MIME type:text/plain
Signature ACRStealer
File name:Qt5Gui.dll
File size:5'978'744 bytes
SHA256 hash: ab160992f30dc69b97feedd2fcaf7528a56fc98a3f30a166c1076589340ac8be
MD5 hash: c4a857dee5656921baba1e19d2b099b6
MIME type:application/x-dosexec
Signature ACRStealer
File name:ApplePushDirect.dll
File size:338'784 bytes
SHA256 hash: 106beed1c918f3e12c3923a24b94eb496745e19eb8baed5453f372a6af6e9797
MD5 hash: 164bfd15b9b72d30fa41f10e74f0fa65
MIME type:application/x-dosexec
Signature ACRStealer
File name:Bass.Net.dll
File size:692'456 bytes
SHA256 hash: 5edc14702b84ebed5653a6cbf64b3a06ffe4e500be10d449a0c68e5a2040f9ef
MD5 hash: e0f9ca774f0e3b40d42de2793f46245a
MIME type:application/x-dosexec
Signature ACRStealer
File name:install_msan_and_race_and_asan_require_cgo.txt
File size:626 bytes
SHA256 hash: 46016efaf824e889b5a6212cecf100dba63ac9bf24b1207e874858b3125d70d6
MD5 hash: 2f92dcb7709e1a004ac580da760bc0b5
MIME type:text/x-c
Signature ACRStealer
File name:max_basiclong_64bit.phpt
File size:940 bytes
SHA256 hash: 4c8900c6494831f78721dd21123d133208f4632eb61c709804a069c007728d8f
MD5 hash: 6382e93a6b45bffc270ee49cbb267660
MIME type:text/plain
Signature ACRStealer
File name:libfaad_plugin.dll
File size:305'792 bytes
SHA256 hash: 829e13951e297db36428c6517c9ed4cd5318aea1c91b6ab58848b93b78fc0091
MD5 hash: 86a0850e26632c5e4c6cc7b429bbc955
MIME type:application/x-dosexec
Signature ACRStealer
File name:VCRUNTIME140.dll
File size:91'216 bytes
SHA256 hash: 63f98f7eb2b42d4e416d1a0e5631becb5ee6ee09393913b4e0d9b4b852355172
MD5 hash: fd82c7b4ee2c40adaae774d7357426d3
MIME type:application/x-dosexec
Signature ACRStealer
File name:session_arginfo.h
File size:12'303 bytes
SHA256 hash: bc4ae9c4d9bf0500d5bb7cd69c5431b23c730b0c5c29631f4e1ac1d43b5617de
MD5 hash: 371bdf86abe0d797e60dec2397fe2b25
MIME type:text/plain
Signature ACRStealer
File name:qopensslbackend.dll
File size:342'720 bytes
SHA256 hash: 478205823c8288cc3b18b78e0a3151a78381d503dbe2bd7df928d79c35969078
MD5 hash: aa98b963d8ef7d4a652fb1b373fcd860
MIME type:application/x-dosexec
Signature ACRStealer
File name:ThirdPartyNotice.txt
File size:271'284 bytes
SHA256 hash: b68a1c6e7a011a9814ef7278552204def242c436ffc14b28cccbd42d1f8dfac3
MD5 hash: 53fad4d375da79354d37162423be9e5b
MIME type:text/plain
Signature ACRStealer
File name:Fee.iuw
File size:19'692 bytes
SHA256 hash: 5a700328c13c23db25e200f8f66bcd9fff085a32a936d6bc9b595c063f5ec9b2
MD5 hash: 1a110b95dc9571d7e974718e258455fa
MIME type:application/octet-stream
Signature ACRStealer
File name:lhs_class_not_found.phpt
File size:217 bytes
SHA256 hash: 9cb272b02e391656b26bcafebccd09eca670fbba010267cefb95b21f25f5818b
MD5 hash: ffa9357224207652acf0edb10a56e05a
MIME type:text/plain
Signature ACRStealer
File name:WRLiloPlugin.dll
File size:931'016 bytes
SHA256 hash: d77df7c23b1a35db633d3930070bd5d87e6c09d7761b3f33b2ef56a5a70b6cab
MD5 hash: b4a1762c306db2d0d2e3cad68a81fbb0
MIME type:application/x-dosexec
Signature ACRStealer
File name:ta.txt
File size:12'935 bytes
SHA256 hash: 0a3b285566bbeb3f188b3c72ba21cbfc545ea05471eab706e972c828da5234e0
MD5 hash: 228ca6d7b8d850853233c4575a7ebf1f
MIME type:text/plain
Signature ACRStealer
File name:gss-server.exe
File size:29'264 bytes
SHA256 hash: a9e161712391bdf611737b538540b4446c252c3d6b0ad0865d0ee23f1ad06e95
MD5 hash: 6c2b5af124b944ffc75ba02e95478a11
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.VisualStudio.DesignTools.Interaction.dll
File size:423'456 bytes
SHA256 hash: 0196a4535f1d893f3caa19b907f945aba13151fe9c3771b4f630ee0a2ee4b86d
MD5 hash: e7dc57afe3b159092e9c5d341ba12eb4
MIME type:application/x-dosexec
Signature ACRStealer
File name:Seatcab.mwkd
File size:753'866 bytes
SHA256 hash: dea73ef806e4dc16bf9796c3fef10448e021b28481ccb68247d53e6f8bf58551
MD5 hash: a6b127c6142c505706900e6791205a84
MIME type:application/octet-stream
Signature ACRStealer
File name:zstd-v0.7-00.result
File size:53 bytes
SHA256 hash: a0e5ea8db3ab4d5f3aba65c8ee5e45dcb0356ce3b385381027a52c33ad928081
MD5 hash: 48f0c54af2e328f37ddf2626598a3d40
MIME type:text/plain
Signature ACRStealer
File name:osclientcerts.dll
File size:366'144 bytes
SHA256 hash: 1d27ad90b99b63b5b5b8dbbe7fc15ef9cbd22e18f33b05cec9e29948b3371883
MD5 hash: 4fb765a04019e46eb8904ee843f4c2bd
MIME type:application/x-dosexec
Signature ACRStealer
File name:gccgo_m.txt
File size:368 bytes
SHA256 hash: 15a66fc3c72f3b98dbd1b799cb8f40dd11d2ea2eef8123c1f42f0ba65711d8b4
MD5 hash: fefcab52a6cae21784cdabfe97828272
MIME type:text/x-c
Signature ACRStealer
File name:odt2txt.exe
File size:62'202 bytes
SHA256 hash: 87ccefd04081c88273f289e38052b172e3607803178593f57547adfcb9a41685
MD5 hash: 7740873b69ed9fbd043883f35625215e
MIME type:application/x-dosexec
Signature ACRStealer
File name:bug42143.phpt
File size:735 bytes
SHA256 hash: 76edf112f74889da33917e573930ae275515cfa6dfaf1b744e7d958e223b5869
MD5 hash: 8029ca5ba29e41d183874040b84e7dca
MIME type:text/plain
Signature ACRStealer
File name:RecipientService.dll
File size:352'920 bytes
SHA256 hash: 1c09795216fa78d2b525e680b74033a54eddfb5f8ba05c382362f8c97f6685f8
MD5 hash: cf0e7aeb9185857936d6b2c1c313bf76
MIME type:application/x-dosexec
Signature ACRStealer
File name:OutlookChangeNotifierAddIn.dll
File size:268'640 bytes
SHA256 hash: a330c2b28422e1694c6539cda7a64da902e6bcd28a5bb0d01b38d17df3a9a932
MD5 hash: caeffb3a2869d5e2fd691d5fee0f5795
MIME type:application/x-dosexec
Signature ACRStealer
File name:tags.txt
File size:14 bytes
SHA256 hash: 447bb964d3975b04dc1693b5562d78c3ba8a2f6510302362a038c7e5c14abc80
MD5 hash: 24748c75c8d7c24613e0d19f9612b58b
MIME type:text/plain
Signature ACRStealer
File name:DisplayLanguageNames.sq.txt
File size:29'020 bytes
SHA256 hash: 8b8625a6c432edd700acd29c85d681a959bf914098afc77e8d0babe697f4c266
MD5 hash: d669755d49955e36a37fcf51bb911c78
MIME type:text/plain
Signature ACRStealer
File name:NamedSequences.txt
File size:20'776 bytes
SHA256 hash: db5745688affcdc0c3927a1ee0667018a96a7b24513f866d5235e98fef6c2436
MD5 hash: 99a6784a1afc07f4b8e3f1e745f420e6
MIME type:text/plain
Signature ACRStealer
File name:ReachFramework.dll
File size:536'576 bytes
SHA256 hash: 7b88af3e38470beaae66c7caa911ff7ba7b085f6ef1a82dd7b2628dc63621e48
MD5 hash: 518c07f3092eba9ac12a28486f69c424
MIME type:application/x-dosexec
Signature ACRStealer
File name:stanpackage.dll
File size:589'192 bytes
SHA256 hash: 1825885def5c04f478c397ee8697f9d13b4bf4af08d76fcb94fd0a29a8298c2d
MD5 hash: cc8e17c7cf64ae4eb160615973518f70
MIME type:application/x-dosexec
Signature ACRStealer
File name:link.txt
File size:527 bytes
SHA256 hash: 3d0ff5df1a7c00c4cc7befd847353dbebdc2eda4426cb5ef87d3f6fd7d378abc
MD5 hash: cd0d8450f629263e63a64d352f9f6ff1
MIME type:text/html
Signature ACRStealer
File name:libhogweed-6.dll
File size:280'131 bytes
SHA256 hash: acf669f5d665c1b42c8073069311de08a872d1b4121e0bf92eafb68e4424c057
MD5 hash: 4dcb8ab70f71fabb672186f5acb1ebe3
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.VisualStudio.DesignTools.WpfTap.dll
File size:475'072 bytes
SHA256 hash: 9811201f2d5e2ca002e1e3fde9fff26926a67108110c3d31eb6c2bb95a8827d0
MD5 hash: 55b667a1d34fda637c8172112f1679f3
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.VisualStudio.Composition.dll
File size:848'808 bytes
SHA256 hash: b0c077b93c2fb417bca1d74a896f30273103c6d238db0b62136452ff7fb4f3e1
MD5 hash: 6d8df72d4baf8feab438c578bfb2e72d
MIME type:application/x-dosexec
Signature ACRStealer
File name:runtime_compile_time_offset_access.phpt
File size:2'634 bytes
SHA256 hash: 826b9eadc889b6634ceec8de0284dd216da27bb38fa00b7f0a357769d7e14dc5
MD5 hash: 46ffd97e5055ec321c368225eb48ea56
MIME type:text/plain
Signature ACRStealer
File name:libnghttp2-14.dll
File size:212'367 bytes
SHA256 hash: fe62132c79637f137e988b560cf756fe40ceba4974c004ef6ec2c63c0ccdaf7b
MD5 hash: 623fc5f3ee3511d9e7a98210e352d895
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.TestPlatform.CrossPlatEngine.dll
File size:678'152 bytes
SHA256 hash: 455719e9561604bfc1a28e886e4ce094beb7b1e3d617e37059f25954fd0ef3c2
MD5 hash: 0caa14a6fb4b6f89c1abb41010996ae5
MIME type:application/x-dosexec
Signature ACRStealer
File name:bug71488.phpt
File size:502 bytes
SHA256 hash: c31eae8d762618ea77f228290f39c241fd31dc3050927a9b58a3458b79834e70
MD5 hash: 35cc18090ea12ab8818d04d771bc3a85
MIME type:text/plain
Signature ACRStealer
File name:Microsoft.Xbox.Tools.CPUProfilers.Analysis.dll
File size:249'640 bytes
SHA256 hash: f5a906741d1c0dd20d1bd20b20b27d3f86dd3ea321ef92f5c23a9e5b29e84a6d
MD5 hash: 6eb7a8449a0b1e787f7559b5310d6a8d
MIME type:application/x-dosexec
Signature ACRStealer
File name:bug53640.phpt
File size:637 bytes
SHA256 hash: b40eaa46874c165eb985adf91fed8759757c09532aa58595fb3681d6b95f9113
MD5 hash: 290affd893e894ca4d1babfe45621a9c
MIME type:text/plain
Signature ACRStealer
File name:help.gl.txt
File size:9'741 bytes
SHA256 hash: 05cdf5a33891882a1b96e007c0ac8dc9f99592f3667f79d83904a38e38e8bbe2
MD5 hash: 14a267cde4ab3ba9bf15d6bac9eddff5
MIME type:text/plain
Signature ACRStealer
File name:et.txt
File size:7'214 bytes
SHA256 hash: d3fc7e1dd6f0486c99997b75d9d8c5592da6cfb9b89c3ec4f59e7bc5826b3456
MD5 hash: 54d610c174514d0f60b382249885963c
MIME type:text/plain
Signature ACRStealer
File name:bug71863.phpt
File size:1'151 bytes
SHA256 hash: c22a9b5dfbf84011c16b2d0a8f3dd72fd6520caa62fa25f7255ab11f2730fd53
MD5 hash: 7dcdf339c264a3b36271858010449b94
MIME type:text/plain
Signature ACRStealer
File name:Microsoft.VisualStudio.WPFFlavor.dll
File size:779'144 bytes
SHA256 hash: 004f3bab54ce7b1f5d5234c63b7c6f4d36354d3aef0c9d5c61c5e5d9469cc596
MD5 hash: 9c8573cc7a91724271a73924a59f05ac
MIME type:application/x-dosexec
Signature ACRStealer
File name:vrfauto.dll
File size:232'936 bytes
SHA256 hash: a64137bfa2e1e4f7e949368655bb679dd7137e4304c4d1441e55fe618f49481f
MD5 hash: d280ae9c6ec751661170109fcb6b0cd2
MIME type:application/x-dosexec
Signature ACRStealer
File name:true_standalone_implicit_nullability.phpt
File size:359 bytes
SHA256 hash: 9b91cf81c200b26681f5a5e77e63bba11f1b4fdedff620d47dbe42daddd57a23
MD5 hash: dac03f1c40c56f6c8cae8298f1c71155
MIME type:text/plain
Signature ACRStealer
File name:cover_dot_import.txt
File size:379 bytes
SHA256 hash: 260d525d2fcd125286a8117daec5a1466413dc53ed9f3e01a0f61a41164d3feb
MD5 hash: 9558c98895f7711c6d600bcf8b5bec42
MIME type:text/plain
Signature ACRStealer
File name:SplDoublylinkedlist_offsetunset_first.phpt
File size:511 bytes
SHA256 hash: ef87eef6b9b5d522e60f2e63cd9c40aab73d8b5f053eaa86f8a4e25412b6c0f4
MD5 hash: a3e06463e66ded1505c2be7b35a028c2
MIME type:text/plain
Signature ACRStealer
File name:Microsoft.SqlServer.GridControl.dll
File size:201'120 bytes
SHA256 hash: c00d09c608a3eccfc3b8c0f7257e0b8555be9168e52633c627495a546e718d4f
MD5 hash: e23b63b2d8aa16936420d206a37d611c
MIME type:application/x-dosexec
Signature ACRStealer
File name:WzWXFlf64.dll
File size:610'968 bytes
SHA256 hash: ea2bc5a01a97a9ec0c117f3b5128bb7d9c4bf328bb96f977e954407e3eb76cb0
MD5 hash: 7ce388a2a61197444ab159dce41c76ef
MIME type:application/x-dosexec
Signature ACRStealer
File name:Microsoft.VisualStudio.LanguageServices.TypeScript.dll
File size:841'648 bytes
SHA256 hash: a488d59e27cc879358a47da891e4f591c2a637a91838adf8462e48659d24b9f9
MD5 hash: 8de98375d649ea6810dae960fe35b82e
MIME type:application/x-dosexec
Signature ACRStealer
File name:DisplayLanguageNames.ti_ET.txt
File size:30'942 bytes
SHA256 hash: 7745073712be850bae2656ab8fe5c590358a9c64e9fd355aee5b5bcaca1023a2
MD5 hash: ac23d1c13fa3df910e68705b5bcd3365
MIME type:text/plain
Signature ACRStealer
File name:build_multi_main.txt
File size:699 bytes
SHA256 hash: b514e6e8e3028a15c6168d8e568c941b6c4f3914203e78a68f3610c6cb2a2292
MD5 hash: f8077cb351530f4c7f8ca61c68d824f4
MIME type:text/x-c
Signature ACRStealer
File name:arrayPointer.phpt
File size:372 bytes
SHA256 hash: 59cee25c85cd57eb57691a7ea535e5f7e032e8c4b5080d16d1568e9682b436a4
MD5 hash: 9de25649d8e040cf56fde86a4f398c68
MIME type:text/plain
Signature ACRStealer
File name:Microsoft.Build.Framework.dll
File size:710'816 bytes
SHA256 hash: 408cda05d006da7a4f186c5510e16c338e7d6b82218fcf30454b7be74464dc33
MD5 hash: 63203b4c6bd194147f37f2c3fec53d94
MIME type:application/x-dosexec
Signature ACRStealer
File name:work_sync_irrelevant_dependency.txt
File size:1'326 bytes
SHA256 hash: ee56da7fecef7d20fab6c51908009c0542a345b27ed07fb4c5200a59936a75db
MD5 hash: 8af60891153aa0a1de83258dbb14fbf8
MIME type:text/plain
Signature ACRStealer
File name:Qt5Core.dll
File size:5'298'296 bytes
SHA256 hash: 9b5473b983c3a773921b9d7a47a44bb07ea102f84d673c214f84accd558299c1
MD5 hash: e7fa5115ae4b7de90e9c4f6808f7475d
MIME type:application/x-dosexec
Signature ACRStealer
File name:i_plugins.txt
File size:13'494 bytes
SHA256 hash: 21b6d0d265b5c37dd0453be92dcfe1e4531c77e092d8c37ce32bcfe160c184bd
MD5 hash: fcb8408aca5e92dc10cf60e50c6de122
MIME type:text/plain
Signature ACRStealer
File name:glass.dll
File size:194'976 bytes
SHA256 hash: a924fba1b393f9231dd181d06f7042a9ca83b34b13f90b781fef72fa129f0205
MD5 hash: e2948a562f2c69946c24175a00b4d842
MIME type:application/x-dosexec
Signature ACRStealer
File name:bug34276.phpt
File size:1'470 bytes
SHA256 hash: fdcd7f24220a3f9269778f606c806c0e96b478205a1f5b334642f399637bcd83
MD5 hash: dc707157bcd07f4c4d1f367776ec2abb
MIME type:text/plain
Signature ACRStealer
File name:embed_brackets.txt
File size:186 bytes
SHA256 hash: eba59931051a8dc019d44d426b96f25fff3a2d5425cea5bffe7bc1a91c0a639d
MD5 hash: 22bb19ce45fb80d4f2405a4501e5ef5a
MIME type:text/plain
Signature ACRStealer
File name:usr_42.txt
File size:13'853 bytes
SHA256 hash: d55bfc3193b85f560d7e76adfb1a0dce5061cf39bc5813fe1b5ef9b652d5e3e3
MD5 hash: 91b16d5ef75b1cf6f30b44f9483bbbfd
MIME type:text/plain
Signature ACRStealer
File name:msg_28.txt
File size:405 bytes
SHA256 hash: d35a4422466b1e62b37425a540c73589435990e56e64619f5b775e19b09a3c80
MD5 hash: 080a9e03cb42f78e3d4d6c0008960f38
MIME type:message/rfc822
Signature ACRStealer
File name:MatrixFactorizationNative.dll
File size:200'832 bytes
SHA256 hash: bc1e41bf01a213396b75e4092d7f1bfca38ac98803719f019f4c8cdee0ec5a38
MD5 hash: b8739f525237deee051b90e42a845c0c
MIME type:application/x-dosexec
Signature ACRStealer
File name:mod_get_errors.txt
File size:1'354 bytes
SHA256 hash: 7c67b91d3d4c7a04362a8e6fd5dd7219e7ac026b2f7f0caa8bcb819e38cb73f6
MD5 hash: 960b647ace3dd9cde820b570675c207b
MIME type:text/plain
Signature ACRStealer
File name:ARE.dll
File size:444'616 bytes
SHA256 hash: 160b6cb95efb7bb4557daf88a5ad48847e610cdcf5e86d3132945099467b019c
MD5 hash: f75983c4dd56e5dd3589dbf466ac86cd
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Gathering data
Gathering data
Result
Gathering data
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive SFX 7z
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

7z 09c4641feea6d8c09f8a9b7b13819172820ef08653758cc14bb2e7fafbf86cc3

(this sample)

  
Delivery method
Distributed via web download

Comments