🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e9a608ea294be64e0da496330b88ca6fab5a76c9e3c3ab24dd7286dd25cd89d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 5


Intelligence 5 IOCs YARA 19 File information Comments

SHA256 hash: 1e9a608ea294be64e0da496330b88ca6fab5a76c9e3c3ab24dd7286dd25cd89d
SHA3-384 hash: 968a31de102c2dfb7075e6b07a6cbcc7895a23004795f7ada5a49abfbf630ec595694a91684ac96f602f3f19c3c644ab
SHA1 hash: 468a9d16c469c2b44237d9dea6aed77b8ff240c9
MD5 hash: 6b135568d86efb2e39c433d0a93d5412
humanhash: massachusetts-potato-pennsylvania-berlin
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:18'337'270 bytes
First seen:2025-05-28 13:57:33 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:BjEFSUxw//ypN/5rN1pden836pnImbEioX2WlBC+a:pfowuNN683InDInB6
TLSH T13D07330297A4809FD53E4B7145D39FA53FA3C1B461AB9A072F7551210FA77282FBABC0
Magika zip
Reporter aachum
Tags:ACRStealer Amadey file-pumped zip


Avatar
iamaachum
https://filespayout.cfd/?LZn94MjyE8HOYUtPo1xQ7eIBXwN3TgpKSiRJFuDr=UtKhS2Rw1afod56mijLHkxsWzFbMOrT93ZuEV4lyCcX=hyzPArH9cEpOI7RiBQwWKf0vquk2ote85L1djbYalSGTUxC&p_title=Adobe-Premiere-Pro-2024-Build-24-2-Crack---Serial-Key-Download&h=40 => https://mega.nz/file/Lt5x1SZZ#XJm-gYXnivmSSqIz4wDOu0R6zB_QhCoNZ8IUN4C48q4

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
ES ES
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:setup.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:769'436'580 bytes
SHA256 hash: 33f15df9504db6cfa7ce68dc74833f815437323047ac678aa104d9b4d93e6167
MD5 hash: f43fb4365ab924f8dac50000ca109fd9
De-pumped file size:18'648'576 bytes (Vs. original size of 769'436'580 bytes)
De-pumped SHA256 hash: e1e799ae737ab78d0218486c1702c1830213b5053f5d4fea9a0a930816c3560c
De-pumped MD5 hash: fa73cd46c555bcc2f8138c5e3f908c09
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Gathering data
Result
Verdict:
Malicious
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-vm bloated borland_delphi crypto fingerprint invalid-signature keylogger large-file overlay overlay packed signed
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Borland
Author:malware-lu
Rule name:HUNTING_SUSP_TLS_SECTION
Author:chaosphere
Description:Detect PE files with .tls section that can be used for anti-debugging
Reference:Practical Malware Analysis - Chapter 16
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:win_rat_generic
Author:Reedus0
Description:Rule for detecting generic RAT malware
Rule name:win_rat_generic
Author:Reedus0
Description:Rule for detecting generic RAT malware
Rule name:with_urls
Author:Antonio Sanchez <asanchez@hispasec.com>
Description:Rule to detect the presence of an or several urls
Reference:http://laboratorio.blogs.hispasec.com/
Rule name:yara_template

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 1e9a608ea294be64e0da496330b88ca6fab5a76c9e3c3ab24dd7286dd25cd89d

(this sample)

Comments