๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 598ea16c40646305a18227410a473eede57009cdc00e793b157239b200964977. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 5


Intelligence 5 IOCs YARA 39 File information Comments

SHA256 hash: 598ea16c40646305a18227410a473eede57009cdc00e793b157239b200964977
SHA3-384 hash: e465b57fd634b7b17bd38536c4abf1228c2d2440d28f17f929f9bb8fdb2be89fcf51459a12fc41c0a2c24a4bb53e9de7
SHA1 hash: 63c44d97a90717795b204f8aa8885148cc0e1c42
MD5 hash: 01ea227967d19c05ce5e67e369a89128
humanhash: hamper-tennessee-texas-fillet
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:3'388'395 bytes
First seen:2025-10-04 00:15:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 98304:9gK4ez8D1y4E6awC9CQnqi0cF3rK0UwU/I5:Ket60nqic0Uwgy
TLSH T10AF5338D76668ABECC3AFF6A7913090C09EF790509B64D14DB047B6F4F95E8E2389704
Magika zip
Reporter aachum
Tags:5-161-95-160 a9321e ACRStealer Amadey HIjackLoader IDATLoader zip


Avatar
iamaachum
https://earshows.xyz/?ejCqvXS-utm=1KsroC => https://mega.nz/file/7wRTADpL#KHyTbQ1Jk0CESUqmvur35-e7F6jL6uae9VxZy3HQWpM

ACRStealer C2: 5.161.95.160
Amadey Botnet: a9321e
Amadey C2: http://mi.barbertingling.com/kaWt2QXfpPueNM/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
96
Origin country :
ES ES
File Archive Information

This file archive contains 30 file(s), sorted by their relevance:

File name:Setup.exe
File size:913'384 bytes
SHA256 hash: ad1730531759670e2c1171e2dc0194f47cc1b3ae40e2afa81528236dac603749
MD5 hash: 7b5edcaa787f8b2f9e66b080d5396aef
MIME type:application/x-dosexec
Signature ACRStealer
File name:MSVCP140.dll
File size:633'152 bytes
SHA256 hash: 517cd3aac2177a357cca6032f07ad7360ee8ca212a02dd6e1301bf6cfade2094
MD5 hash: 9ff712c25312821b8aec84c4f8782a34
MIME type:application/x-dosexec
Signature ACRStealer
File name:vcruntime140_1.dll
File size:49'792 bytes
SHA256 hash: e30b3f4979b63b50438d061858c9cde962f4494e585c627a11c98b6c5b7b2592
MD5 hash: 851760a3cc87354e057985e42e69f425
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature ACRStealer
File name:Zeengtholshoort.phl
File size:20'042 bytes
SHA256 hash: 3f0fbde30ae49ed588b6882d3bea531910ef689fbcb20f197141b7b4356916c6
MD5 hash: d7dc84c1d2b24687e0fd8e724d9ad76d
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:Resource.ct
File size:3'136'432 bytes
SHA256 hash: 37a5a53b7d95439b05b5e4f394de8b931a500f6df97aaf1a82cb8a66c11478f2
MD5 hash: cf83372ce8462708f58817b1560e7006
MIME type:application/x-dosexec
Signature ACRStealer
File name:VCRUNTIME140.dll
File size:87'888 bytes
SHA256 hash: d89c7b863fc1ac3a179d45d5fe1b9fd35fb6fbd45171ca68d0d68ab1c1ad04fb
MD5 hash: edf9d5c18111d82cf10ec99f6afa6b47
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature ACRStealer
File name:Shulgend.wu
File size:811'294 bytes
SHA256 hash: 2837f2a62e8ae0c7d5beea7437f94483ef2aaccfda49c2c592d5ab4bb316deb0
MD5 hash: 886fb64c12c3bea89f793bed7ede3d59
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature ACRStealer
File name:UpdateClient.prx
File size:373'656 bytes
SHA256 hash: 7fa86147035627bae39576bcbe619d045e94a48c4db8ca131968c20bb4de4a36
MD5 hash: 14934caca84d5fe0288f27efb31dcbf8
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature ACRStealer
File name:UpdateClient.dll
File size:65'856 bytes
SHA256 hash: e113f8593244c1bb5bcc73fef0f93303c783714162cbd9ef93ddff5709c037ce
MD5 hash: 760f24f0150a6e8dc15ac793c3172387
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature ACRStealer
File name:mozglue.dll
File size:167'912 bytes
SHA256 hash: 048d83df38eb4befb4127406871e043e5b63aa36ab62d32b846bb10070bd415b
MD5 hash: ca52212011191040d4ad8fbc9b8a9568
MIME type:application/x-dosexec
Signature ACRStealer
File name:xmlrw.dll
File size:341'952 bytes
SHA256 hash: 8968104a0d9a2b7e321ecafb271bb0319871e2db2ac0db29df96856bebea46d6
MD5 hash: 94b1d34efb234ffca5943fe5b0fc2b17
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
injection obfusc agent
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
expired-cert fingerprint microsoft_visual_cc overlay packed signed
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.31 Zip Archive
Threat name:
Win64.Trojan.Rugmi
Status:
Malicious
First seen:
2025-10-03 21:34:39 UTC
File Type:
Binary (Archive)
Extracted files:
193
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
amaterastealer hijackloader
Similar samples:
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercรชs
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:extracted_at_0x44b
Author:cb
Description:sample - file extracted_at_0x44b.exe
Reference:Internal Research
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_EXE_Packed_SmartAssembly
Author:ditekSHen
Description:Detects executables packed with SmartAssembly
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 598ea16c40646305a18227410a473eede57009cdc00e793b157239b200964977

(this sample)

Comments