MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 891d72fb2ca2334c93df5ceab0001b7d26202f36b0e23af250fceb8629629d41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Aurotun


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 891d72fb2ca2334c93df5ceab0001b7d26202f36b0e23af250fceb8629629d41
SHA3-384 hash: e4c11e732e81f1b18b13c5a66caac47877f5ea6fc06a7fab665fe76eebbac1f6a0574d5727d8ddda2b74e8232baa6fbd
SHA1 hash: 992c3fdcf9b60c2fb8d6328ec50a9d3e667565ae
MD5 hash: bd2ec35005acdd2ba702120fa2d0e854
humanhash: vermont-connecticut-maryland-green
File name:DGQRGFSN.zip
Download: download sample
Signature Aurotun
File size:97'579'418 bytes
First seen:2025-06-04 08:25:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:d3PaVaJLA+u+JxTndtwOJ5nX4LRMKF43I1Jrlmnq/LGfoBShyZ/C7fIVQxSYeuRz:1YWLP/JxJRILRMKFAYrz0oUhyZB2SYee
TLSH T1CD2833CAD0DEA9B2F42B0F5EC4D91CF028C839735B335965EC04D2CA537B9896972789
Magika zip
Reporter JAMESWT_WT
Tags:Aurotun clickcease-biz zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
220
Origin country :
IT IT
File Archive Information

This file archive contains 11 file(s), sorted by their relevance:

File name:MSVCP140.dll
File size:436'600 bytes
SHA256 hash: 51398691feef7ae0a876b523aec47c4a06d9a1ee62f1a0aee27de6d6191c68ad
MD5 hash: 8ff1898897f3f4391803c7253366a87b
MIME type:application/x-dosexec
Signature Aurotun
File name:libcrypto-1_1.dll
File size:1'668'848 bytes
SHA256 hash: 14c64e71a3f1edac861370abe291eeee4dbf5ea4a83315ca2fe07c40d4fdd84a
MD5 hash: 9aeb2d782c07245e1f065ffdd63ba7e8
MIME type:application/x-dosexec
Signature Aurotun
File name:Fland.clt
File size:93'664'166 bytes
SHA256 hash: bd096e192869c281f7a88ba731f06c08c049b64a7e30a51ca67355e5067d69ab
MD5 hash: 226729c2fadc5bbe275863ebb0aae7ca
MIME type:application/octet-stream
Signature Aurotun
File name:cfg.ini
File size:23 bytes
SHA256 hash: 0d2634560aa03ba83883e6a3e3095d5c944dde55418a26716332d6e819e266da
MD5 hash: 1f702f72181d314c1315c78065856d6c
MIME type:application/x-setupscript
Signature Aurotun
File name:DiskInfo.dll
File size:2'137'072 bytes
SHA256 hash: ad8556c031a9917745fe92533a6e354b7f97996ab02e2d6cda3cc72e621f1947
MD5 hash: 624ea2b0697fe8ef58088090a1cf5442
MIME type:application/x-dosexec
Signature Aurotun
File name:Ato_Control38.exe
File size:5'246'192 bytes
SHA256 hash: c0f46a2a7d2f054527f80edc235051031f3b55e78ecbfd9aeaa77e1ff8b9411c
MD5 hash: 54f78cffeeb539528818737505eb8a6f
MIME type:application/x-dosexec
Signature Aurotun
File name:VCRUNTIME140.dll
File size:76'168 bytes
SHA256 hash: 9faeaa45e8cc986af56f28350b38238b03c01c355e9564b849604b8d690919c5
MD5 hash: 1a84957b6e681fca057160cd04e26b27
MIME type:application/x-dosexec
Signature Aurotun
File name:Thealgeend.znqo
File size:82'308 bytes
SHA256 hash: b422f696af1bde7a23b478a79d8fe502bf24c320982c0a4bbbf2a0c86f5f11d6
MD5 hash: 805eb77ec35b6737ba8408e73430c509
MIME type:application/octet-stream
Signature Aurotun
File name:WebView2Loader.dll
File size:115'632 bytes
SHA256 hash: d6f70c734b09917e1ef9abc54a0edc84afea3f784e31c8ec75fb525b2821eee5
MD5 hash: 8fb7d2fa445716d23433ee696d41387d
MIME type:application/x-dosexec
Signature Aurotun
File name:mfc140u.dll
File size:5'127'088 bytes
SHA256 hash: e422c9366a53536a35e307ef301f08661c28c29b7fcda1b454333c6a41c6bb21
MD5 hash: e76b52d11db435d36453d26c8b446a8f
MIME type:application/x-dosexec
Signature Aurotun
File name:Up.dll
File size:603'376 bytes
SHA256 hash: 57972c5ce575ea09835212dba27791f33b8f07980bba69393d75b1cc20d58a6c
MD5 hash: 14bf5d3b181d00eaa72e0fe4a3c4d138
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
injection dropper virus
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context anti-vm base64 expand fingerprint lolbin microsoft_visual_cc overlay signed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Gathering data
Result
Malware family:
aurotun
Score:
  10/10
Tags:
family:aurotun discovery stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Checks computer location settings
Suspicious use of SetThreadContext
Looks up external IP address via web service
Aurotun
Aurotun family
Detects Aurotun stealer
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 891d72fb2ca2334c93df5ceab0001b7d26202f36b0e23af250fceb8629629d41

(this sample)

  
Delivery method
Distributed via web download

Comments