๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 978bc1b4d043ac0f287b62a98443ed77e7b6e4e267b266cc429901c45fee76be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 5


Intelligence 5 IOCs YARA 35 File information Comments

SHA256 hash: 978bc1b4d043ac0f287b62a98443ed77e7b6e4e267b266cc429901c45fee76be
SHA3-384 hash: 71a52ed0e94be48bb514f9e9b3646fdce80ec3b1b21d4e81028d4e06fffb4742d3d52d10abb78a658f550622900502fe
SHA1 hash: 9c3c3e42a806d1a4b62fce230a3e8ba93f652dfa
MD5 hash: 47b14e652a1257c8f80189563203161b
humanhash: happy-sierra-cola-island
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:3'021'372 bytes
First seen:2025-10-04 00:03:03 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 49152:qF1Vwlg7fUYo8CQrCIHpJReZuUQfW+RiWzp0cka0wPoWj5Qa7JyX10f/vRuN33Pg:spgYo8CcJLeQUknLp0Y0wPoeUFA/vRuq
TLSH T1AAE533C5085845C89AA3273732FBB57E8C715798B89CF9DD8E7C04138A89AEF59142FC
Magika zip
Reporter aachum
Tags:178-156-181-202 a9321e ACRStealer Amadey HIjackLoader IDATLoader zip


Avatar
iamaachum
https://habitnest.icu/ => https://mega.nz/file/n0Jm1QAD#_3oBsySX-f-hG9dpVbL5PiNdCpAwgK0Vt3QaPpEwAoc

Amadey Botnet: a9321e
Amadey C2: http://mi.barbertingling.com/kaWt2QXfpPueNM/index.php
ACRStealer C2: 178.156.181.202

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
ES ES
File Archive Information

This file archive contains 30 file(s), sorted by their relevance:

File name:CDWizard.ini
File size:356 bytes
SHA256 hash: ea942a06a90ce414ec09f0bee074bde052b9edd0868d6cde2559a02a4c73548f
MD5 hash: d0e26cba6cd4df48f97e1b56405a558f
MIME type:application/x-wine-extension-ini
Signature ACRStealer
File name:Setup.exe
File size:121'376 bytes
SHA256 hash: 509c1f6d5ac9a0e5eea7697777dd4c88a5b178d4726c3d1184a0f04bdf95e5af
MD5 hash: d64d4a56dbc8146e40e9d7007c0cee1d
MIME type:application/x-dosexec
Signature ACRStealer
File name:MSVCP140.dll
File size:447'568 bytes
SHA256 hash: 654412a50c83d218d9f72f8bbd0e0d2963ed0b58be59d6661e931f32dc9f80d8
MD5 hash: 05f1b8a11885aa248408597f25ee9d47
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature ACRStealer
File name:CDWizard.log
File size:835 bytes
SHA256 hash: 88cf69384c4e6479b782372f7f8f1be468f96250e76e5ada4a92452a6bed5310
MD5 hash: 5c054dc0dded802bcc6edea6aa79c88b
MIME type:text/plain
Signature ACRStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:Resource.ct
File size:3'136'432 bytes
SHA256 hash: 37a5a53b7d95439b05b5e4f394de8b931a500f6df97aaf1a82cb8a66c11478f2
MD5 hash: cf83372ce8462708f58817b1560e7006
MIME type:application/x-dosexec
Signature ACRStealer
File name:VCRUNTIME140.dll
File size:91'216 bytes
SHA256 hash: 63f98f7eb2b42d4e416d1a0e5631becb5ee6ee09393913b4e0d9b4b852355172
MD5 hash: fd82c7b4ee2c40adaae774d7357426d3
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature ACRStealer
File name:Veelfleamim.rndm
File size:819'498 bytes
SHA256 hash: 79f9322ba1943784455754ad0fa5ed5b418438b8e72af98ac1203264633a8bb9
MD5 hash: c7b4813157b91423b9478a5bdbdd22b9
MIME type:application/octet-stream
Signature ACRStealer
File name:Greatcootraing.dkq
File size:26'393 bytes
SHA256 hash: b7f45dde6d3a29a8b4327d77be22baf437d82080b98855d8e861a9c3cdf4ea18
MD5 hash: e6eec9b7afb49d5dd045aa67195cae1b
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature ACRStealer
File name:UpdateClient.prx
File size:373'656 bytes
SHA256 hash: 7fa86147035627bae39576bcbe619d045e94a48c4db8ca131968c20bb4de4a36
MD5 hash: 14934caca84d5fe0288f27efb31dcbf8
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature ACRStealer
File name:UpdateClient.dll
File size:65'856 bytes
SHA256 hash: e113f8593244c1bb5bcc73fef0f93303c783714162cbd9ef93ddff5709c037ce
MD5 hash: 760f24f0150a6e8dc15ac793c3172387
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature ACRStealer
File name:CDWizard.DLL
File size:805'408 bytes
SHA256 hash: 61741f791b5bc3308f57363b415350f5aa1d4b5912c9ccf132f3bf8fd1228096
MD5 hash: bcbcb46c2b724586410e152c8fd623f7
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
injection obfusc agent
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
expired-cert fingerprint microsoft_visual_cc overlay packed signed
Verdict:
Clean
File Type:
zip
First seen:
2025-10-04T15:09:00Z UTC
Last seen:
2025-10-04T15:16:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.31 Zip Archive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-02 20:39:32 UTC
File Type:
Binary (Archive)
Extracted files:
187
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__MemoryWorkingSet
Author:Fernando Mercรชs
Description:Anti-debug process memory working set size check
Reference:http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerHiding__Thread
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:extracted_at_0x44b
Author:cb
Description:sample - file extracted_at_0x44b.exe
Reference:Internal Research
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:INDICATOR_EXE_Packed_SmartAssembly
Author:ditekSHen
Description:Detects executables packed with SmartAssembly
Rule name:Indicator_MiniDumpWriteDump
Author:Obscurity Labs LLC
Description:Detects PE files and PowerShell scripts that use MiniDumpWriteDump either through direct imports or string references
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip 978bc1b4d043ac0f287b62a98443ed77e7b6e4e267b266cc429901c45fee76be

(this sample)

  
Delivery method
Distributed via web download

Comments