🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3c2d602ddfa3fb7fdc5aedc735a07cab7ee70a77e739070538d03dca17cd579d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 5 File information Comments

SHA256 hash: 3c2d602ddfa3fb7fdc5aedc735a07cab7ee70a77e739070538d03dca17cd579d
SHA3-384 hash: df67fff9f14341588a0f34880fcd88c24b47b5792a665c730c1e2e402f8e70b409318ab9d413117db64f271b269fb45f
SHA1 hash: fb9b2d7c05088bbde599efa521888c7cdac0de3f
MD5 hash: ee116e25d12d750979ea54b7527cf371
humanhash: one-video-east-avocado
File name:3c2d602ddfa3fb7f.bin
Download: download sample
Signature ACRStealer
File size:96'211 bytes
First seen:2026-09-30 06:25:31 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 1536:be1FJGsdpjk0oNuPtgtQCTpnF9Q90adz4zcpNpfO+GL1jfrwNdJ9/qSw7ieYi:bkF8spjPyuP+JpF9Q9Pz4zWOL1jfUn7u
TLSH T1109322053B8C95E010CDDDBE0FC06CA956AEE072D3DADC9C66CF5A84AB43AFA459C474
Magika powershell
Reporter whack_sh
Tags:ACRStealer powershell ps1

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 crypto dropper encrypted evasive fingerprint lolbin masquerade msbuild powershell
Verdict:
Malicious
File Type:
ps1
First seen:
2026-09-28T03:01:00Z UTC
Last seen:
2026-10-01T21:58:00Z UTC
Hits:
~10
Result
Threat name:
Arechclient2
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Creates a thread in another existing process (thread injection)
Creates an undocumented autostart registry key
Creates processes via WMI
Early bird code injection technique detected
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Monitors registry run keys for changes
Multi AV Scanner detection for submitted file
Powershell connects to network
Powershell drops PE file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queues an APC in another process (thread injection)
Sigma detected: Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Rundll32 Execution Without CommandLine Parameters
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Yara detected Arechclient2
Yara detected Powershell decode and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1979808 Sample: 3c2d602ddfa3fb7f.bin.ps1 Startdate: 30/09/2026 Architecture: WINDOWS Score: 100 111 upstream.foxtrail.vip 2->111 113 header.flavorroute.cc 2->113 115 9 other IPs or domains 2->115 141 Suricata IDS alerts for network traffic 2->141 143 Found malware configuration 2->143 145 Malicious sample detected (through community Yara rule) 2->145 147 12 other signatures 2->147 11 powershell.exe 44 2->11         started        15 AutoIt3.exe 2->15         started        17 wscript.exe 2->17         started        19 4 other processes 2->19 signatures3 process4 file5 107 C:\Users\user\AppData\...\4dap3kys.cmdline, Unicode 11->107 dropped 189 Suspicious powershell command line found 11->189 191 Suspicious execution chain found 11->191 193 Found suspicious powershell code related to unpacking or dynamic code loading 11->193 207 2 other signatures 11->207 21 powershell.exe 15 20 11->21         started        25 csc.exe 3 11->25         started        28 csc.exe 3 11->28         started        30 conhost.exe 11->30         started        109 C:\Users\user\AppData\Roaming\...\RegAsm.exe, PE32+ 15->109 dropped 195 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 15->195 197 Writes to foreign memory regions 15->197 199 Modifies the context of a thread in another process (thread injection) 15->199 201 Injects a PE file into a foreign processes 15->201 32 RegAsm.exe 15->32         started        203 Windows Scripting host queries suspicious COM object (likely to drop second stage) 17->203 34 AutoIt3.exe 17->34         started        205 Found direct / indirect Syscall (likely to bypass EDR) 19->205 36 msedge.exe 19->36         started        signatures6 process7 dnsIp8 119 raw.githubusercontent.com 185.199.110.133, 443, 49724 FASTLY-FastlyIncUS United States 21->119 121 rawcdn.githack.com 104.26.0.171, 443, 49722 CLOUDFLARENET-CloudflareIncUS Canada 21->121 157 Early bird code injection technique detected 21->157 159 Found many strings related to Crypto-Wallets (likely being stolen) 21->159 161 Suspicious execution chain found 21->161 171 3 other signatures 21->171 38 rundll32.exe 21->38         started        42 conhost.exe 21->42         started        103 C:\Users\user\AppData\Local\...\4dap3kys.dll, PE32 25->103 dropped 44 cvtres.exe 1 25->44         started        105 C:\Users\user\AppData\Local\...\bw0kcozy.dll, PE32 28->105 dropped 46 cvtres.exe 1 28->46         started        123 178.104.144.200, 443, 49755 HETZNER-ASDE Germany 32->123 163 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 32->163 165 Tries to harvest and steal browser information (history, passwords, etc) 32->165 167 Writes to foreign memory regions 32->167 173 2 other signatures 32->173 48 chrome.exe 32->48         started        50 chrome.exe 32->50         started        169 Found direct / indirect Syscall (likely to bypass EDR) 34->169 file9 signatures10 process11 dnsIp12 125 json.snippetlabs.tech 38->125 127 imap.quietfox.cc 38->127 129 11 other IPs or domains 38->129 175 System process connects to network (likely due to code injection or exploit) 38->175 177 Suspicious powershell command line found 38->177 179 Found many strings related to Crypto-Wallets (likely being stolen) 38->179 181 5 other signatures 38->181 52 powershell.exe 38->52         started        55 powershell.exe 38->55         started        59 msedge.exe 38->59         started        69 5 other processes 38->69 61 chrome.exe 48->61 injected 63 WerFault.exe 48->63         started        65 chrome.exe 50->65 injected 67 WerFault.exe 50->67         started        signatures13 process14 dnsIp15 149 Powershell connects to network 52->149 71 AutoIt3.exe 52->71         started        75 conhost.exe 52->75         started        131 upstream.foxtrail.vip 104.21.17.72, 443, 49748, 49754 CLOUDFLARENET-CloudflareIncUS Canada 55->131 99 C:\Users\user\AppData\Roaming\...\AutoIt3.exe, PE32+ 55->99 dropped 101 C:\Users\user\AppData\Roaming\...\Fabrics.a3x, data 55->101 dropped 151 Creates an undocumented autostart registry key 55->151 77 conhost.exe 55->77         started        153 Monitors registry run keys for changes 59->153 79 msedge.exe 59->79         started        81 WerFault.exe 61->81         started        133 local.recliner.cc 104.21.12.242, 443, 49750 CLOUDFLARENET-CloudflareIncUS Canada 69->133 135 127.0.0.1 unknown unknown 69->135 155 Unusual module load detection (module proxying) 69->155 83 chrome.exe 69->83         started        86 pingsender.exe 69->86         started        88 conhost.exe 69->88         started        file16 signatures17 process18 dnsIp19 95 C:\Users\user\AppData\Local\...\AutoIt3.exe, PE32+ 71->95 dropped 97 C:\Users\user\AppData\...\LinkTurtle.vbs, ASCII 71->97 dropped 183 Modifies the context of a thread in another process (thread injection) 71->183 185 Injects a PE file into a foreign processes 71->185 187 Found direct / indirect Syscall (likely to bypass EDR) 71->187 90 AutoIt3.exe 71->90         started        117 www.google.com 142.251.153.119, 443, 49734, 49739 GOOGLE-GoogleLLCUS United States 83->117 93 conhost.exe 86->93         started        file20 signatures21 process22 dnsIp23 137 header.flavorroute.cc 104.21.80.112, 443, 49757 CLOUDFLARENET-CloudflareIncUS Canada 90->137 139 aaf0e58824b44ab71.awsglobalaccelerator.com 76.223.55.101, 443, 49756 AMAZON-02-AmazoncomIncUS United States 90->139
Verdict:
Malware
YARA:
2 match(es)
Tags:
Base64 Block Contains Base64 Block DeObfuscated PowerShell T1027 T1059.001 T1105
Threat name:
Win32.Trojan.Pantera
Status:
Malicious
First seen:
2026-09-28 09:21:45 UTC
File Type:
Text (PowerShell)
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Result
Malware family:
sectoprat
Score:
  10/10
Tags:
family:acrstealer family:sectoprat defense_evasion discovery execution persistence privilege_escalation rat spyware stealer trojan
Behaviour
Uses Task Scheduler COM API
Suspicious use of WriteProcessMemory
Suspicious use of SetWindowsHookEx
Suspicious use of SendNotifyMessage
Suspicious use of FindShellTrayWindow
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious behavior: MapViewOfSection
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: EnumeratesProcesses
Modifies registry class
Modifies data under HKEY_USERS
Modifies Control Panel
Enumerates system info in registry
Checks processor information in registry
Enumerates physical storage devices
Browser Information Discovery
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
System Time Discovery
Suspicious use of SetThreadContext
Enumerates connected drives
Contacts third-party web service commonly abused for C2
Command and Scripting Interpreter: PowerShell
Checks installed software on the system
Adds Run key to start application
Accesses cryptocurrency files/wallets, possible credential harvesting
Registers new Windows logon scripts automatically executed at logon.
Reads user/profile data of web browsers
Reads user/profile data of local email clients
Executes dropped EXE
Creates a file in the Startup directory
Badlisted process makes network request
Suspicious use of NtCreateUserProcessOtherParentProcess
Family: SectopRAT
Family: ACR stealer,GrMsk
Detects SectopRAT aka Arechclient2
Malware Config
C2 Extraction:
imap.quietfox.cc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:OBFUS_PowerShell_Common_Replace
Author:SECUINFRA Falcon Team
Description:Detects the common usage of replace for obfuscation
Rule name:Suspicious_PS_Strings
Author:Lucas Acha (http://www.lukeacha.com)
Description:observed set of strings which are likely malicious, observed with Jupyter malware.
Reference:http://security5magics.blogspot.com/2020/12/tracking-jupyter-malware.html
Rule name:SUSP_PowerShell_Base64_Decode
Author:SECUINFRA Falcon Team
Description:Detects PowerShell code to decode Base64 data. This can yield many FP
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

PowerShell (PS) ps1 3c2d602ddfa3fb7fdc5aedc735a07cab7ee70a77e739070538d03dca17cd579d

(this sample)

  
Delivery method
Distributed via web download

Comments