🀲🏼 NEW | abuse.ch Community Hub! Earn recognition πŸ… for the malware intelligence you share, climb the leaderboards πŸ“ˆ, and connect with like-minded contributors who share your hunting focus 🀝. Ready to unlock your profile? Go to the Community Hub β†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64ba3fc1ca2e8e2f79c88d7e68a368a45cf8bc7a39a796ff499743f0e066cb2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 3


Intelligence 3 IOCs YARA 4 File information Comments

SHA256 hash: 64ba3fc1ca2e8e2f79c88d7e68a368a45cf8bc7a39a796ff499743f0e066cb2d
SHA3-384 hash: 0e9ce38dbce1a8ae807c62774395aebbe29645d4830a5d18ff4fb78d475013faf1e44deb45c0c98285d334d4b22f4b72
SHA1 hash: 310254fef3bbf9f5649c0e5bfe5b757f0ea81099
MD5 hash: e652fb8194b0893e55b79f4fe8e69685
humanhash: ink-finch-muppet-august
File name:γ€Ž πƒπ•†π™’ππ•ƒπŽπ”Έπƒ γ€βž€ 𝐒𝐄𝐓𝐔𝐏 ➀ 𝓀𝐏𝐃𝐀𝐓𝐄 ➀ 𝐍𝐄𝐖.7z
Download: download sample
Signature ACRStealer
File size:9'069'905 bytes
First seen:2025-10-11 09:58:59 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
Note:This file is a password protected archive. The password is: 2025
ssdeep 196608:W+iI2th8yrSYSgZfFZZgtzrTnE/vVWHE7xZeXwTyrU+x:WNz84ZfF7gdrbE/MkV4XRUe
TLSH T1D1963354E74921280796F764863898E6745830CE5F478F568300FF1A9FBF3AFA1FA0A5
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:7z 827ad8 ACRStealer Amadey HIjackLoader pw-2025


Avatar
iamaachum
https://cludchpfile.click/?uid=280&sid=279&lp=kbPYuslBqg => https://mega.nz/file/fsgAzbIB#Q6IU0msa4i4ANWu08JAV_SRJ_5sBBK8E78M1fKCRIqk

Amadey Botnet: 827ad8
Amadey C2: http://mi.limpingbronco.com/kaWt2QXfpPueNM/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
181
Origin country :
ES ES
File Archive Information

This file archive contains 46 file(s), sorted by their relevance:

File name:Setup.exe
File size:258'752 bytes
SHA256 hash: 090695c6be6698cb8bbef8cc300bb332e77b5b618047da07556ca1e1e7e0c354
MD5 hash: 7b6545f47523e87c40f3f29a9067ba1f
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature ACRStealer
File name:netstandard.dll
File size:101'160 bytes
SHA256 hash: 57f9beafe45cce172d363928f126936a274958b6d357455d368d9f9a2be16f1c
MD5 hash: ea0e593c338c61277f41823d982b374e
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.ComponentModel.dll
File size:31'032 bytes
SHA256 hash: 145bef6f199664ad1f534120056906dad4a1a6766a9cb0501b8125cc3fddf9df
MD5 hash: af5df602d830cd5d828113e6ed63167b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature ACRStealer
File name:NvStWiz.prx
File size:442'680 bytes
SHA256 hash: c2ad5bd189df04b39be18dec5cd251cf79b066010706ad26d99df7e49fd07762
MD5 hash: 9e82e3b658393bed3f7e4f090df1fbe7
MIME type:application/x-dosexec
Signature ACRStealer
File name:NLog.dll
File size:925'184 bytes
SHA256 hash: 030350bbe5d0b52528c1fd00fbc59ea25c745b4b724acd3efc370fc9d8263791
MD5 hash: 3b1e3153b115b871695f66b67bf39dd9
MIME type:application/x-dosexec
Signature ACRStealer
File name:hostfxr.dll
File size:350'504 bytes
SHA256 hash: da1923422f7a7180ff9cc28ae632f3a16051ce625ec919b8f45fcb07f92fe7a8
MD5 hash: b3555e7fe065645329ea42cfea1ca14d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.IO.FileSystem.Watcher.dll
File size:88'360 bytes
SHA256 hash: be143d5f41a244f2f65ca7f8db25143465b89959b042d4889b0bd72f422138db
MD5 hash: cb69acedd5e18601548c3ac8bb2d8106
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Linq.dll
File size:543'024 bytes
SHA256 hash: 64acd73260b864145c835de0a0d535b0aec1ab10cf4708c1b56797ddefd0a678
MD5 hash: fb0fb17b3a25ff482c63087e2ce4f73a
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Collections.dll
File size:260'392 bytes
SHA256 hash: 06ac8c082896fe8c2c3ebcfe2966e467838118fc2ea54185f808ebb3f37ddad4
MD5 hash: 73a0e6ace4b9b392a348e20d527a6278
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Runtime.dll
File size:43'696 bytes
SHA256 hash: 2849a7089c9a96c027caff7350af131e630e4e7b6edb268b7ab880569358100d
MD5 hash: adb7dcabdb8cbde702a302cb166ad7a4
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Net.Mail.dll
File size:432'424 bytes
SHA256 hash: a1a0bf958fc9a991badebf285e110e8f2128bcaedd6ded5408d4c805ccbb2d3c
MD5 hash: 1d5efdf9c466a25998a77c2e75ab1f65
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Private.CoreLib.dll
File size:13'170'952 bytes
SHA256 hash: 6b18dc1feaf9ceb49cf5b173a1543b41a304dc5ceef32a612ad77fd13e02eee7
MD5 hash: 59f8c0b86e0dcf6a6a3395947407a783
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.ObjectModel.dll
File size:80'168 bytes
SHA256 hash: 381fc44114bd420c0855469395876a962f8cd752a6621cafc3bcad5c8e131970
MD5 hash: df2793c6fe44c1e75b5d901c306fe24e
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature ACRStealer
File name:Surfshark.Antivirus.ContextMenu.Commands.dll
File size:157'376 bytes
SHA256 hash: a03494a67e84725291cc53bcc3aee55d7ae4311bada0114ddab71e9ba7f40bd0
MD5 hash: e58702f06b79eaaa60b37e2a2b2c9569
MIME type:application/x-dosexec
Signature ACRStealer
File name:Ungros.ldx
File size:9'342 bytes
SHA256 hash: aef35324950cd56bfbbd4de22eeb6a0f814a3f67703580be1f5aeee7cf3982a4
MD5 hash: 99dd78543d252807702b19f1f6056e44
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Net.Primitives.dll
File size:231'584 bytes
SHA256 hash: a9284ab30bfb4540cba15d51fdd44b33e30a764db0b42c31eb79bf7e9dc55120
MD5 hash: 0fec078018a0e485b45e789fb75cb614
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Threading.dll
File size:84'144 bytes
SHA256 hash: d822696f2831fe562be2e91621382951500d34a49171e8165b5255426ddb5c20
MD5 hash: d414ae2b0f7ce818c4514c4891e2d1a8
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.ComponentModel.Primitives.dll
File size:80'168 bytes
SHA256 hash: fa581d2aa20bac7d159a56911cc469784aa9a7ff816115499eeacce85fbc989c
MD5 hash: 8c50946b498caf0cf9a78420a1c62084
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature ACRStealer
File name:hostpolicy.dll
File size:393'376 bytes
SHA256 hash: d4d9db2cee70e6ad857188f12f92a0532be6f7fc7412851c8ed54afdc30ccbcd
MD5 hash: 061a29ca4f11abab79b7c49980294f06
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Private.Uri.dll
File size:260'360 bytes
SHA256 hash: 2492c5f7e779359d09740cb776cd41a726cd4f0ccdd65dd64d5e6f5a81e6df54
MD5 hash: e620d27381add0d057a62d1c63df896e
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Diagnostics.StackTrace.dll
File size:47'400 bytes
SHA256 hash: c8d73c39097c08d5836360c5012be01c3409ecdd8b34310ac25c638775efcfd6
MD5 hash: 15e2f39b879cddf1eaddf2a134d3e738
MIME type:application/x-dosexec
Signature ACRStealer
File name:ks_tyres.ini
File size:10'077 bytes
SHA256 hash: 894d3c57598ecb22c769cc3ea8219859a95e22740e72394a474012ea2119b3d9
MD5 hash: 47f6571c7884da6c743551ac724186d4
MIME type:text/plain
Signature ACRStealer
File name:config.prx
File size:373'656 bytes
SHA256 hash: 7fa86147035627bae39576bcbe619d045e94a48c4db8ca131968c20bb4de4a36
MD5 hash: 14934caca84d5fe0288f27efb31dcbf8
MIME type:application/x-dosexec
Signature ACRStealer
File name:clrjit.dll
File size:1'785'136 bytes
SHA256 hash: bb68bf2c02422190fca77a823f9cd38ea2bb97ed9bcfd16cdc424c2e5f3de6bb
MD5 hash: 463e4a8ff3ca41f30303ac50bd0ab343
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature ACRStealer
File name:coreclr.dll
File size:5'040'800 bytes
SHA256 hash: 9d79227e61dc4e51b098c070d6fd38090a1b5fbb4f1e91c4db3cbe97b16deefd
MD5 hash: 0d38f891849e6b7204ecd4d1958d4faf
MIME type:application/x-dosexec
Signature ACRStealer
File name:Coulwongflook.bml
File size:835'906 bytes
SHA256 hash: 604c8e5c069eb3d790616bf1f85092f91da69949e4eac34ab2de6e34be1e912e
MD5 hash: 82b186742bca7ce3b23604cee8c4ad8e
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature ACRStealer
File name:System.Threading.ThreadPool.dll
File size:16'168 bytes
SHA256 hash: 0112b653d00ae32bdc9c1217e0aa0995a17b1e58af1e614ea4c7a3dece699ef8
MD5 hash: 25c5170fc2185493a30bcd3a6922e84b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive SFX 7z
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-11 10:01:05 UTC
File Type:
Binary (Archive)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

7z 64ba3fc1ca2e8e2f79c88d7e68a368a45cf8bc7a39a796ff499743f0e066cb2d

(this sample)

  
Delivery method
Distributed via web download

Comments