🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 258bd09ae466b4590060a1c9057744f73d4e1a20d51684a6ec705d6464e6c573. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 258bd09ae466b4590060a1c9057744f73d4e1a20d51684a6ec705d6464e6c573
SHA3-384 hash: 0abfe72dc939707c1a297cbfcec3b4a6f4bdb2c3af2e21815e003d0428c8bb751836b0dbafdf53ffe4f96f5aeb1e2728
SHA1 hash: a6f59489d57def1d32d7e40025263170767cd1af
MD5 hash: 97679b1291ee9e51e0ab025eb5f3d5e9
humanhash: minnesota-sixteen-oscar-monkey
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:12'476'069 bytes
First seen:2025-10-27 14:58:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:fbdvLhzadXtJGIjla+ANFHk5lkEQMwSVTYQa/oduUZWrcGgB23xMo/KXp/TZx:jdvLhzGXycM9k5lj4Q0UZNo/KXp/TD
TLSH T1CFC6334D82BD71EDE13047F875A38A9194192B35DAB8C79E4BE0072B96CF4DAC8533C9
Magika zip
Reporter aachum
Tags:46-224-8-58 74a65b ACRStealer Amadey HIjackLoader IDATLoader zip


Avatar
iamaachum
https://fighthem.space/ => https://mega.nz/file/EYcBFIYI#NBoRGUpeJXjZ4HEfZBy0Euc_8ReBAumk7fuVlPg_a6M

ACRStealer C2: 46.224.8.58
Amadey Botnet: 74a65b
Amadey C2: http://mi.overlapsnowbound.com/kaWt2QXfpPueNM/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
154
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug embarcadero_delphi expired-cert fingerprint invalid-signature overlay packed signed
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.19 SOS: 0.21 SOS: 0.24 SOS: 0.25 SOS: 0.26 SOS: 0.27 SOS: 0.28 SOS: 0.29 SOS: 0.31 SOS: 0.34 SOS: 0.37 SOS: 0.40 SOS: 0.43 SOS: 0.46 Zip Archive
Threat name:
Win32.Trojan.Hijackloader
Status:
Suspicious
First seen:
2025-10-27 15:01:25 UTC
File Type:
Binary (Archive)
Extracted files:
386
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader defense_evasion discovery execution spyware trojan
Behaviour
Command and Scripting Interpreter: JavaScript
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 258bd09ae466b4590060a1c9057744f73d4e1a20d51684a6ec705d6464e6c573

(this sample)

  
Delivery method
Distributed via web download

Comments