MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 726a8b7b87c7aab20c1e204aac06c71cadc8320fd9338cdd61af0e4f5d3a8b01. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 726a8b7b87c7aab20c1e204aac06c71cadc8320fd9338cdd61af0e4f5d3a8b01
SHA3-384 hash: a56c40630cd29c2499d34f21b44b25f10617f4626a04ad0c5cf59c7290fbade4c62f16710de901c9100f3f6c34d0ab04
SHA1 hash: a02ff9674040ff9f70c6d832bac4ebc0607e717b
MD5 hash: d64d34892f5731688fc0825f38bff57d
humanhash: pizza-arkansas-twenty-illinois
File name:of.zip
Download: download sample
Signature ACRStealer
File size:16'200'438 bytes
First seen:2026-03-01 11:56:53 UTC
Last seen:2026-03-02 07:26:16 UTC
File type: zip
MIME type:application/zip
ssdeep 393216:50aia+q9CHothqgoIidJwAwNFzF3XUyYjdh/r7bs1dQnSO5Y:KY+q90obxL2/wt3XBo/r0DQSO5Y
TLSH T198F63320AB6916E7E3F6713EB6319107A450B2F8D913FE8F758CC0E746C3BE19226951
Magika zip
Reporter aachum
Tags:77-238-228-60 ACRStealer ClickFix FakeCaptcha zip


Avatar
iamaachum
https://hostingcdn.click/of.zip

ACRStealer C2: 77.238.228.60

Intelligence


File Origin
# of uploads :
2
# of downloads :
130
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
malware
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-01 11:57:36 UTC
File Type:
Binary (Archive)
Extracted files:
2811
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments