🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46fcdef3fc081c8de5f687e5fb1a1e9cc597cef94c996154b5c85912f1506ba4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 46fcdef3fc081c8de5f687e5fb1a1e9cc597cef94c996154b5c85912f1506ba4
SHA3-384 hash: f613ab120466b79fc0f8f15ca166cb002ef6e64e55d5644a73c4906674a7b322b4a7e31fc723c4fa042a463333a402c1
SHA1 hash: 562a96528bdd01f258e950c224c769fd35d9cc6a
MD5 hash: baddbccad0733c684c6f86c418ae401c
humanhash: west-batman-maryland-hamper
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:12'151'153 bytes
First seen:2026-07-26 18:47:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:Heq8Dne/gMB2Rd2nGJvhlPziS33ceHZMOWKcXBP/15qhBb8nkWR+gKUvvM7:Hl8Dntj3zlLiS33ceHWMcht5qh/cTKG4
TLSH T1C2C61294D5FB4907CF0EB6FAB0CA81969DEDCBCA59205E23043C73CA5C965B10BD660E
TrID 66.6% (.XPI) Mozilla Firefox browser extension (8000/1/1)
33.3% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter aachum
Tags:ACRStealer logs-workflowengine-cc zip


Avatar
iamaachum
https://tsdnvtrk.it.com/ => https://www.mediafire.com/file/yg320ivly1fmcgj/SETUP_FILE_(PASS_KEY=9095).zip/file

ACRStealer C2: logs.workflowengine.cc

Intelligence


File Origin
# of uploads :
1
# of downloads :
108
Origin country :
ES ES
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Swrort
Status:
Suspicious
First seen:
2026-07-26 18:48:39 UTC
File Type:
Binary (Archive)
Extracted files:
2263
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 46fcdef3fc081c8de5f687e5fb1a1e9cc597cef94c996154b5c85912f1506ba4

(this sample)

  
Delivery method
Distributed via web download

Comments