🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1c498b3ba5d3c2c62bbd17ae695748466dd63bf852551d919f44ff91c628dca0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 5


Intelligence 5 IOCs YARA 22 File information Comments

SHA256 hash: 1c498b3ba5d3c2c62bbd17ae695748466dd63bf852551d919f44ff91c628dca0
SHA3-384 hash: 70cb924d6edca503ce1fd3ef09f36ecdefc14872c5f69768de5f8e1009a2f4c969c84388b705d40a24879d7ec425c2d8
SHA1 hash: 8af42f401befd1656f2b3fbb48c3b9fd016746db
MD5 hash: 3df1bf18e0f6cc5cd05436eed41a940e
humanhash: nebraska-carbon-whiskey-coffee
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:29'589'455 bytes
First seen:2025-11-02 13:50:27 UTC
Last seen:2025-11-04 14:54:06 UTC
File type: zip
MIME type:application/zip
ssdeep 786432:8Xo0SSrzO03qjdCAoZTJHI0eIeQgk199HN7GJ4VTP0:8XoT2zOwqf6I4sa9HNgCs
TLSH T15D573371D0992CE8C8723C95F359696A639F731DA13503EE13322BC2E9FB79053EA449
Magika zip
Reporter aachum
Tags:2265ca 46-62-192-15 ACRStealer Amadey HIjackLoader IDATLoader zip


Avatar
iamaachum
https://macsfixedfiles.icu/ => https://mega.nz/file/eV92XDaT#zIjfdCyLYCOmB2jkzqiUK9_gGY6qQkV2zZVNUa4g9lg

ACRStealer C2: 46.62.192.15
Amadey Botnet: 2265ca
Amadey C2: http://mi.huffproofs.com/kaWt2QXfpPueNM/index.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
186
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
stealer extens micro
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
expired-cert microsoft_visual_cc signed
Verdict:
Unknown
File Type:
zip
First seen:
2025-11-02T10:46:00Z UTC
Last seen:
2025-11-03T05:23:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.18 SOS: 0.19 SOS: 0.21 SOS: 0.24 SOS: 0.25 SOS: 0.27 SOS: 0.28 SOS: 0.32 SOS: 0.33 SOS: 0.37 SOS: 0.50 Zip Archive
Gathering data
Threat name:
Win32.Trojan.Hijackloader
Status:
Suspicious
First seen:
2025-10-31 14:27:03 UTC
File Type:
Binary (Archive)
Extracted files:
587
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader defense_evasion discovery persistence privilege_escalation spyware trojan
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:extracted_at_0x44b
Author:cb
Description:sample - file extracted_at_0x44b.exe
Reference:Internal Research
Rule name:golang
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:ScanStringsInsocks5systemz
Author:Byambaa@pubcert.mn
Description:Scans presence of the found strings using the in-house brute force method
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:win_hookinjex_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.hookinjex.
Rule name:with_urls
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the presence of an or several urls
Reference:http://laboratorio.blogs.hispasec.com/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 1c498b3ba5d3c2c62bbd17ae695748466dd63bf852551d919f44ff91c628dca0

(this sample)

  
Delivery method
Distributed via web download

Comments