๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26245cb54eac3f16e56ccf7b65a8d7f71c1da2bcd896d97603ca164deb4efd1d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 4


Intelligence 4 IOCs YARA 37 File information Comments

SHA256 hash: 26245cb54eac3f16e56ccf7b65a8d7f71c1da2bcd896d97603ca164deb4efd1d
SHA3-384 hash: 9c10a95425a8dd43066f927307bae7772457220fe3e15854a83817c74ddf2f9e79438b219ebe201416ba4ad31eab699c
SHA1 hash: aaf3a347b3a792df0e986957e3d25732860002b3
MD5 hash: 822aaba3952a8ba7363236ffdf2b7ed0
humanhash: cardinal-spaghetti-zebra-sweet
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:18'470'332 bytes
First seen:2025-10-14 19:15:45 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:Ga0EZnzOZQkqKD4UxqR1bIwPzPamDiU95x6XI3WrBqWnwgjph4aEEK:GZEU7q44Ux+nCm1fItlBwi6
TLSH T1C117338DD7D0ACDF683EC1199930031DDDF6E02B8D991D2A7EA5163E5CDABDC32AA011
Magika zip
Reporter aachum
Tags:827ad8 91-99-156-25 ACRStealer Amadey HIjackLoader IDATLoader zip


Avatar
iamaachum
https://earshows.xyz/?EGazHGw-utm=1U42LO => https://mega.nz/file/4J0yVJBJ#J8pOJuCUojrAKW3uI-fgEAGer-tbH02L_nLCzQCOyOw

ACRStealer C2: 91.99.156.25
Amadey C2: http://mi.limpingbronco.com/kaWt2QXfpPueNM/index.php
Amadey Botnet: 827ad8

Intelligence


File Origin
# of uploads :
1
# of downloads :
140
Origin country :
ES ES
File Archive Information

This file archive contains 49 file(s), sorted by their relevance:

File name:libintl-9.dll
File size:475'769 bytes
SHA256 hash: 1125ac8dc0c4f5c3ed4712e0d8ad29474099fcb55bb0e563a352ce9d03ef1d78
MD5 hash: e79e7c9d547ddbee5c8c1796bd092326
MIME type:application/x-dosexec
Signature ACRStealer
File name:Setup.exe
File size:1'369'896 bytes
SHA256 hash: bcf14b97a2ee13e4d0002a95c07fc67a759305df2f2abb862aea995a3e0bdd5c
MD5 hash: f0dd700f023074454175cf4d933ab58e
MIME type:application/x-dosexec
Signature ACRStealer
File name:MSVCP140.dll
File size:627'992 bytes
SHA256 hash: 99e3e25cda404283fbd96b25b7683a8d213e7954674adefa2279123a8d0701fd
MD5 hash: c1b066f9e3e2f3a6785161a8c7e0346a
MIME type:application/x-dosexec
Signature ACRStealer
File name:Gortfrood.yx
File size:23'955 bytes
SHA256 hash: 23a8b1e40ef015299e77808ab07e4ea3480904fc6a196f0f65c0559f28e9b9bb
MD5 hash: d266c1e7a2295fb105e67f19b3a1d759
MIME type:application/octet-stream
Signature ACRStealer
File name:vcruntime140_1.dll
File size:49'792 bytes
SHA256 hash: e30b3f4979b63b50438d061858c9cde962f4494e585c627a11c98b6c5b7b2592
MD5 hash: 851760a3cc87354e057985e42e69f425
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature ACRStealer
File name:libssl-1_1-x64.dll
File size:688'128 bytes
SHA256 hash: 084e7b541c8a17ad47425315406bbf894f116d2268924afdb48b153945390a12
MD5 hash: fb679642d779095cae2ec7e5f83f8321
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature ACRStealer
File name:NvStWiz.prx
File size:442'680 bytes
SHA256 hash: c2ad5bd189df04b39be18dec5cd251cf79b066010706ad26d99df7e49fd07762
MD5 hash: 9e82e3b658393bed3f7e4f090df1fbe7
MIME type:application/x-dosexec
Signature ACRStealer
File name:57
File size:6'144 bytes
SHA256 hash: a9b0ca1bb4c99fca93b1ece69f09ab3258670184b0de208a6d85abe33b39cbf2
MD5 hash: d2536efea1d8d1899837eb0c5e30a21a
MIME type:application/octet-stream
Signature ACRStealer
File name:tradingnetworkingsockets.dll
File size:4'249'928 bytes
SHA256 hash: fc4a65ff603bf1f4bfe323de1866145ae1e006aa656799fd134dfa63d92d47c1
MD5 hash: 3cf26ce759c5e261fe3ecc6451b8b08e
MIME type:application/x-dosexec
Signature ACRStealer
File name:45
File size:20'480 bytes
SHA256 hash: 56386729bea1c92b691e458d83a4af3951193f180beb036acf5c9b22bc31a90c
MD5 hash: ff28e179325783eaedfe913a6dab90d0
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature ACRStealer
File name:Stood.mra
File size:835'906 bytes
SHA256 hash: 434f5cd050657392f0b05221e69439435c0d0d782208adfc658638782e7c4fc7
MD5 hash: d1de818e726c1ca7f1e0006d30bc2b92
MIME type:application/octet-stream
Signature ACRStealer
File name:opengl64.dll
File size:18'578'896 bytes
SHA256 hash: dd575f3c64382193610815909bd2c52490244ecbbb9bba6eef5fe4f0bb43bb4d
MD5 hash: 0a84667145e7efef026c888d4b768126
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:4
File size:1'536 bytes
SHA256 hash: be3691988dd3742082c0c2c96eb0ff26821bdfabcbbe39e730775e08904ef58c
MD5 hash: cba55530200e8e33bb8f33e570cde4dc
MIME type:application/octet-stream
Signature ACRStealer
File name:81
File size:94'720 bytes
SHA256 hash: 1b9acbbe674e08a0feedfca6f8119f342cd8317d5527897de4611cab3d5a777c
MD5 hash: 7176b1b2d4a448df85a1f127cfdbfe32
MIME type:application/octet-stream
Signature ACRStealer
File name:libssl-3-x64.dll
File size:745'984 bytes
SHA256 hash: 715caf4d1b3c0322327dabac25c89f3629f0c03d92b12d25ea5d727ffea096e9
MD5 hash: 558b37d852846944851bf796437e33c8
MIME type:application/x-dosexec
Signature ACRStealer
File name:VCRUNTIME140.dll
File size:109'392 bytes
SHA256 hash: a8f950b4357ec12cfccddc9094cca56a3d5244b95e09ea6e9a746489f2d58736
MD5 hash: 4585a96cc4eef6aafd5e27ea09147dc6
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature ACRStealer
File name:COFF_SYMBOLS
File size:64'121 bytes
SHA256 hash: 09842a504ac9b017b6dc509132978ae4cd47cf37e87c6bc96c5692b14d0abea3
MD5 hash: c94222820b6ff0004967225e66bff345
MIME type:application/octet-stream
Signature ACRStealer
File name:libcrypto-3-x64.dll
File size:4'348'416 bytes
SHA256 hash: 046a1360c3d438b28783004607be5fdbcd97e952eb46ac7bc74628b4f705cdea
MD5 hash: ded38e4e513bd187e705bdb46544e82b
MIME type:application/x-dosexec
Signature ACRStealer
File name:31
File size:15'360 bytes
SHA256 hash: c6dcbb26d26a5bcccc3e6d51567f7e6289db705d7718b723cd354eb2a77b8786
MD5 hash: b4a04c73bc76010bf15fa8c26aeaa14b
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature ACRStealer
File name:libiconv-2.dll
File size:1'850'401 bytes
SHA256 hash: 3ee9786ab3eb8dfd791bdbd17c7e791dbe025734befcded0ee4170e1089f79df
MD5 hash: 64d9b3280e9abc2f9882463ceb265803
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature ACRStealer
File name:trading_api64.dll
File size:289'568 bytes
SHA256 hash: f1eb582e607a1e43cdb1654bfb7cb29ad46f6728b3fb89a14f7727e0e8daab69
MD5 hash: 2bca4e2c047ec969cb3cff277e7fc184
MIME type:application/x-dosexec
Signature ACRStealer
File name:70
File size:3'072 bytes
SHA256 hash: b26839b76bd0848c2c3cf286d044b89c1916632ecd8a3b4ade0f01d7c4252660
MD5 hash: 0b4427bfc028cef643024a2b2ba0a709
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature ACRStealer
File name:LIBPQ.dll
File size:312'832 bytes
SHA256 hash: af65d47d830dc2f370936da6e5887bfb6f8ba75203bfb14181cd4236c19c839f
MD5 hash: de753a56e1fdf1a7ab3c093b6182e1a0
MIME type:application/x-dosexec
Signature ACRStealer
File name:libwinpthread-1.dll
File size:52'736 bytes
SHA256 hash: ffe2d56375bb4e8bdee9037df6befc5016ddd8871d0d85027314dd5792f8fdc9
MD5 hash: 9dc829c2c8962347bc9adf891c51ac05
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature ACRStealer
File name:libcrypto-1_1-x64.dll
File size:3'441'152 bytes
SHA256 hash: bbadb15e542fe9c65f28621201c86e08faae64a8c4828363c8d69b86b3fe5ac1
MD5 hash: d2f9c4d2f51b62336a5103d6c78e41f7
MIME type:application/x-dosexec
Signature ACRStealer
File name:92
File size:15'872 bytes
SHA256 hash: 512c3f34f17336d898c1276b4c2a62c63cc5ba6a34e426ab3f6de46af8a47f34
MD5 hash: 395d7414aa77c77feff98365587b83b4
MIME type:application/octet-stream
Signature ACRStealer
File name:ks_tyres.ini
File size:10'077 bytes
SHA256 hash: 894d3c57598ecb22c769cc3ea8219859a95e22740e72394a474012ea2119b3d9
MD5 hash: 47f6571c7884da6c743551ac724186d4
MIME type:text/plain
Signature ACRStealer
File name:config.prx
File size:373'656 bytes
SHA256 hash: 7fa86147035627bae39576bcbe619d045e94a48c4db8ca131968c20bb4de4a36
MD5 hash: 14934caca84d5fe0288f27efb31dcbf8
MIME type:application/x-dosexec
Signature ACRStealer
File name:libmysql.dll
File size:7'186'584 bytes
SHA256 hash: a97f6114bc594051e81fdc902ec42c6d09f489dce6c7529df9279be287902d9e
MD5 hash: 037a8c3bc5c30b4055d427358788dc6c
MIME type:application/x-dosexec
Signature ACRStealer
File name:19
File size:133'120 bytes
SHA256 hash: d3f8585321613405a3a40a5d4f176cc9ff54f50dbe7860384f3569b604a77335
MD5 hash: 07a693ce6754b19891fba75f5aad3213
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc crypt
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
expired-cert fingerprint microsoft_visual_cc overlay packed signed
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win64.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-14 16:53:19 UTC
File Type:
Binary (Archive)
Extracted files:
108
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercรชs
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Glasses
Author:Seth Hardy
Description:Glasses family
Rule name:GlassesCode
Author:Seth Hardy
Description:Glasses code features
Rule name:golang
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:INDICATOR_KB_CERT_62e745e92165213c971f5c490aea12a5
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:skip20_sqllang_hook
Author:Mathieu Tartare <mathieu.tartare@eset.com>
Description:YARA rule to detect if a sqllang.dll version is targeted by skip-2.0. Each byte pattern corresponds to a function hooked by skip-2.0. If $1_0 or $1_1 match, it is probably targeted as it corresponds to the hook responsible for bypassing the authentication.
Reference:https://www.welivesecurity.com/
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_Generic_MassHunt_Win_Malware_2025_CYFARE
Author:CYFARE
Description:Generic Windows malware mass-hunt rule - 2025
Reference:https://cyfare.net/
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants
Rule name:win_iconic_stealer_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.iconic_stealer.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 26245cb54eac3f16e56ccf7b65a8d7f71c1da2bcd896d97603ca164deb4efd1d

(this sample)

  
Delivery method
Distributed via web download

Comments