MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0eb055536e5f198f1c9b7113bc4e5693207a78002f6dc3a356b8820ca99cffae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Aurotun


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0eb055536e5f198f1c9b7113bc4e5693207a78002f6dc3a356b8820ca99cffae
SHA3-384 hash: 1737f9e699adb3d11074f13c6e4a105c7083cbb0dd6423f50f897003fd0134b7be89163283c4f47b58da1eb14dfdc238
SHA1 hash: 3a9f6fc6ffe0a93d7f54c93a90dcc34e64c0bc36
MD5 hash: f03c30f6ecd71086bdcae7958f2751be
humanhash: carbon-spring-ack-alpha
File name:TOTGZDTT.zip
Download: download sample
Signature Aurotun
File size:97'457'175 bytes
First seen:2025-06-04 08:26:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:y3PaY2ffs+eHXWUsaYgAkMqD9Vdxg4GpjhoDqzxja1L8cu8cP2Nl8Re5NArXIfeI:w/w0qURHaqDLlGD0P1LTc+84evZ1w
TLSH T14B283364DDEEA63EED9F48267A106EA467C770D77F3416E0C912C3C0794C7224AAE394
Magika zip
Reporter JAMESWT_WT
Tags:Aurotun clickcease-biz zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
303
Origin country :
IT IT
File Archive Information

This file archive contains 12 file(s), sorted by their relevance:

File name:MSVCP140.dll
File size:436'600 bytes
SHA256 hash: 51398691feef7ae0a876b523aec47c4a06d9a1ee62f1a0aee27de6d6191c68ad
MD5 hash: 8ff1898897f3f4391803c7253366a87b
MIME type:application/x-dosexec
Signature Aurotun
File name:libcrypto-1_1.dll
File size:1'668'848 bytes
SHA256 hash: 14c64e71a3f1edac861370abe291eeee4dbf5ea4a83315ca2fe07c40d4fdd84a
MD5 hash: 9aeb2d782c07245e1f065ffdd63ba7e8
MIME type:application/x-dosexec
Signature Aurotun
File name:Fland.clt
File size:93'467'270 bytes
SHA256 hash: 2fd4a1495928a16b23ae4a68252d0b0f963b3e62e321f1f11dc4e5799135b1f5
MD5 hash: a5b6313cb03aecfd83fa17030aade82b
MIME type:application/octet-stream
Signature Aurotun
File name:cfg.ini
File size:23 bytes
SHA256 hash: 0d2634560aa03ba83883e6a3e3095d5c944dde55418a26716332d6e819e266da
MD5 hash: 1f702f72181d314c1315c78065856d6c
MIME type:application/x-setupscript
Signature Aurotun
File name:DiskInfo.dll
File size:2'137'072 bytes
SHA256 hash: ad8556c031a9917745fe92533a6e354b7f97996ab02e2d6cda3cc72e621f1947
MD5 hash: 624ea2b0697fe8ef58088090a1cf5442
MIME type:application/x-dosexec
Signature Aurotun
File name:Ato_Control38.exe
File size:5'246'192 bytes
SHA256 hash: c0f46a2a7d2f054527f80edc235051031f3b55e78ecbfd9aeaa77e1ff8b9411c
MD5 hash: 54f78cffeeb539528818737505eb8a6f
MIME type:application/x-dosexec
Signature Aurotun
File name:VCRUNTIME140.dll
File size:76'168 bytes
SHA256 hash: 9faeaa45e8cc986af56f28350b38238b03c01c355e9564b849604b8d690919c5
MD5 hash: 1a84957b6e681fca057160cd04e26b27
MIME type:application/x-dosexec
Signature Aurotun
File name:Thealgeend.znqo
File size:82'308 bytes
SHA256 hash: b422f696af1bde7a23b478a79d8fe502bf24c320982c0a4bbbf2a0c86f5f11d6
MD5 hash: 805eb77ec35b6737ba8408e73430c509
MIME type:application/octet-stream
Signature Aurotun
File name:2
File size:145 bytes
SHA256 hash: d2952e57023848a37fb0f21f0dfb38c9000f610ac2b00c2f128511dfd68bde04
MD5 hash: f7ad1eab748bc07570a57ec87787cf90
MIME type:text/xml
Signature Aurotun
File name:WebView2Loader.dll
File size:115'632 bytes
SHA256 hash: d6f70c734b09917e1ef9abc54a0edc84afea3f784e31c8ec75fb525b2821eee5
MD5 hash: 8fb7d2fa445716d23433ee696d41387d
MIME type:application/x-dosexec
Signature Aurotun
File name:mfc140u.dll
File size:5'127'088 bytes
SHA256 hash: e422c9366a53536a35e307ef301f08661c28c29b7fcda1b454333c6a41c6bb21
MD5 hash: e76b52d11db435d36453d26c8b446a8f
MIME type:application/x-dosexec
Signature Aurotun
File name:Up.dll
File size:603'376 bytes
SHA256 hash: 57972c5ce575ea09835212dba27791f33b8f07980bba69393d75b1cc20d58a6c
MD5 hash: 14bf5d3b181d00eaa72e0fe4a3c4d138
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
injection dropper virus
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context anti-vm base64 expand fingerprint lolbin microsoft_visual_cc overlay signed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Gathering data
Result
Malware family:
aurotun
Score:
  10/10
Tags:
family:aurotun discovery stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: LoadsDriver
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Checks computer location settings
Suspicious use of SetThreadContext
Looks up external IP address via web service
Aurotun
Aurotun family
Detects Aurotun stealer
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 0eb055536e5f198f1c9b7113bc4e5693207a78002f6dc3a356b8820ca99cffae

(this sample)

  
Delivery method
Distributed via web download

Comments