🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3092b23e18d2a9c3d6f0a974455439d7c4e34a928ea380219ea4a1037cc22064. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3092b23e18d2a9c3d6f0a974455439d7c4e34a928ea380219ea4a1037cc22064
SHA3-384 hash: c7fa2f0cd54cb7871b8bd110fee77f3ec4aacac166056ed16aa0e70a695a856117ca9f59caf14b7f0190987e99cc7346
SHA1 hash: e5e50ddd26bd0d6b7f92006388e22451a2a202b6
MD5 hash: 9f20fca08728c1d39e9e764433b00b00
humanhash: missouri-alpha-kitten-illinois
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:12'478'961 bytes
First seen:2025-10-25 15:24:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:Rn/l/fO6Ux4Hqxl8/zFG9AYy695TL9oIg+bbdiuAr/qPYnsLwgItLXGEOzNVI1pt:rfOhplOM93y6LPyI3WryzMtzGEOcH7Vn
TLSH T1E8C6333CC0AC359EE833C5B190EE03BAF598771921727CD0ECA1997C76E569AA37419C
Magika zip
Reporter aachum
Tags:46-224-8-58 74a65b ACRStealer Amadey HIjackLoader IDATLoader zip


Avatar
iamaachum
https://fighthem.space/ => https://mega.nz/file/UVsgwCTb#gNkoY4r_3AZRkk7G89iaPJFz9gj5ObJdeDn6wKK_i7E

ACRStealer C2: 46.224.8.58
Amadey Botnet: 74a65b
Amadey C2: http://mi.overlapsnowbound.com/kaWt2QXfpPueNM/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug embarcadero_delphi expired-cert fingerprint invalid-signature overlay packed signed
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.19 SOS: 0.21 SOS: 0.24 SOS: 0.25 SOS: 0.26 SOS: 0.27 SOS: 0.28 SOS: 0.29 SOS: 0.31 SOS: 0.34 SOS: 0.37 SOS: 0.40 SOS: 0.43 SOS: 0.46 Zip Archive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-25 15:25:42 UTC
File Type:
Binary (Archive)
Extracted files:
386
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 3092b23e18d2a9c3d6f0a974455439d7c4e34a928ea380219ea4a1037cc22064

(this sample)

  
Delivery method
Distributed via web download

Comments