MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b4fc704f7a53929ab614c2fc68bb63b85f901043375914a4e92cd0a8d32d643. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 7 File information Comments

SHA256 hash: 9b4fc704f7a53929ab614c2fc68bb63b85f901043375914a4e92cd0a8d32d643
SHA3-384 hash: 52e11f648393bfa355a60f304ddb22473d9e1f4d19a8c3090afaf96a854a73210a51c6d15b40c549e002af43d6a12560
SHA1 hash: b88ab0fbf814ed90523ae152caff3046f5863e66
MD5 hash: 55086caf39129a111ae656fed7976469
humanhash: golf-jersey-two-delaware
File name:Azure.exe
Download: download sample
Signature ACRStealer
File size:1'619'456 bytes
First seen:2026-07-30 08:17:36 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 013c74198fc6e42dcf33737d6c40c012 (11 x RedLineStealer, 7 x Stealc, 4 x NanoCore)
ssdeep 24576:QnTY4LWrzJEdOPl3EuMaPn8C5FAAojYunEPAsc1g1pVhUCBglF1VSk0qEIwdC:ckPrM8ujswg1pVhQTVF0qf
TLSH T106752382E6E50437FDF3A7B440B5054BB27631886B39C2EB365085893E632C9BD7539B
TrID 89.3% (.EXE) Win32 MS Cabinet Self-Extractor (WExtract stub) (303567/2/11)
4.8% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
1.9% (.EXE) Win64 Executable (generic) (6522/11/2)
1.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.6% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon a8341271b1b25aa8 (1 x ACRStealer)
Reporter burger
Tags:ACRStealer exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
182
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
Archives AutoIt
Details
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Creating a window
DNS request
Unauthorized injection to a recently created process
Deleting a recently created file
Unauthorized injection to a recently created process by context flags manipulation
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug autoit CAB expired-cert explorer fingerprint installer installer installer-heuristic invalid-signature keylogger lolbin microsoft_visual_cc packed reconnaissance rundll32 runonce sfx signed
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-30T05:22:00Z UTC
Last seen:
2026-07-31T22:20:00Z UTC
Hits:
~100
Detections:
Backdoor.Win32.Agent.myxhxt Backdoor.Agent.UDP.C&C
Result
Threat name:
ACR Stealer, Xmrig
Detection:
malicious
Classification:
evad.troj.spyw.mine
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Creates / moves files in alternative data streams (ADS)
Creates an undocumented autostart registry key
Detected potential unwanted application
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Found strings related to Crypto-Mining
Injects a PE file into a foreign processes
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Modifies windows update settings
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
PE file contains section with special chars
Performs DNS queries to domains with low reputation
Protects its processes via BreakOnTermination flag
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Sample is not signed and drops a device driver
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Schedule system process
Sigma detected: Suspicious Script Execution From Temp Folder
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Unusual module load detection (module proxying)
Uses cmd line tools excessively to alter registry or file data
Uses nslookup.exe to query domains
Uses schtasks.exe or at.exe to add and modify task schedules
Verifies if a H.264 Video Encoder exists (likely to detect the VM)
Writes to foreign memory regions
Yara detected ACR Stealer
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1949991 Sample: Azure.exe Startdate: 30/07/2026 Architecture: WINDOWS Score: 100 136 serve.eastpeak.xyz 2->136 138 rpc.sentio.xyz 2->138 140 7 other IPs or domains 2->140 170 Suricata IDS alerts for network traffic 2->170 172 Malicious sample detected (through community Yara rule) 2->172 174 Antivirus detection for URL or domain 2->174 178 10 other signatures 2->178 13 Azure.exe 4 2->13         started        16 LockAppHost14a02b.exe 2->16         started        19 UsoClient34ed49.exe 2->19         started        21 SmartScreenHost27dac.exe 2->21         started        signatures3 176 Performs DNS queries to domains with low reputation 138->176 process4 file5 126 C:\Users\user\AppData\Local\...\AutoIt3.exe, PE32+ 13->126 dropped 23 AutoIt3.exe 13->23         started        160 Antivirus detection for dropped file 16->160 162 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 16->162 164 Uses nslookup.exe to query domains 16->164 168 4 other signatures 16->168 166 Found direct / indirect Syscall (likely to bypass EDR) 19->166 26 schtasks.exe 19->26         started        signatures6 process7 signatures8 208 Modifies the context of a thread in another process (thread injection) 23->208 210 Tries to detect virtualization through RDTSC time measurements 23->210 212 Injects a PE file into a foreign processes 23->212 214 2 other signatures 23->214 28 AutoIt3.exe 82 23->28         started        33 conhost.exe 26->33         started        process9 dnsIp10 156 193.233.75.215, 49902, 80 DHOST-ASRU Germany 28->156 158 push.brewtrail.click 104.21.54.19, 443, 49886, 49887 CLOUDFLARENET-CloudflareIncUS Canada 28->158 128 C:\Users\user\AppData\...\wx2x06sm58.exe, PE32+ 28->128 dropped 130 C:\Users\user\AppData\...\t464954bgd.exe, PE32+ 28->130 dropped 132 C:\Users\user\AppData\...\biq6xu9p0d.exe, PE32+ 28->132 dropped 134 2 other malicious files 28->134 dropped 216 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 28->216 218 Creates / moves files in alternative data streams (ADS) 28->218 220 Tries to harvest and steal ftp login credentials 28->220 222 3 other signatures 28->222 35 t464954bgd.exe 98 28->35         started        40 biq6xu9p0d.exe 28->40         started        42 wx2x06sm58.exe 10 28->42         started        44 4z6edve56t.exe 28->44         started        file11 signatures12 process13 dnsIp14 144 polygon.gateway.tenderly.co 35.227.193.242 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 35->144 146 serve.eastpeak.xyz 104.21.82.184 CLOUDFLARENET-CloudflareIncUS Canada 35->146 112 C:\Users\...\SmartScreenHost27dac.exe (copy), PE32+ 35->112 dropped 188 Antivirus detection for dropped file 35->188 190 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 35->190 192 Suspicious powershell command line found 35->192 202 4 other signatures 35->202 46 explorer.exe 35->46 injected 49 schtasks.exe 35->49         started        51 powershell.exe 35->51         started        114 C:\Users\user\...\MusNotificationce794c.exe, PE32+ 40->114 dropped 116 :x (copy), PE32+ 40->116 dropped 194 Creates / moves files in alternative data streams (ADS) 40->194 196 Creates an undocumented autostart registry key 40->196 198 Found direct / indirect Syscall (likely to bypass EDR) 40->198 53 MusNotificationce794c.exe 40->53         started        118 C:\Users\user\AppData\...\UsoClient34ed49.exe, PE32+ 42->118 dropped 120 :n (copy), PE32+ 42->120 dropped 200 Uses schtasks.exe or at.exe to add and modify task schedules 42->200 56 UsoClient34ed49.exe 33 42->56         started        58 schtasks.exe 1 42->58         started        122 C:\ProgramData\...\LockAppHost14a02b.exe, PE32+ 44->122 dropped 124 :r (copy), PE32+ 44->124 dropped 60 sc.exe 44->60         started        62 sc.exe 44->62         started        64 sc.exe 44->64         started        file15 signatures16 process17 dnsIp18 224 Uses nslookup.exe to query domains 46->224 66 nslookup.exe 46->66         started        71 conhost.exe 49->71         started        73 conhost.exe 51->73         started        148 polygon.drpc.org 104.18.11.59 CLOUDFLARENET-CloudflareIncUS Canada 53->148 150 route.techquarter.xyz 172.67.168.32 CLOUDFLARENET-CloudflareIncUS Canada 53->150 152 polygon-bor-rpc.publicnode.com 172.66.150.162 CLOUDFLARENET-CloudflareIncUS Canada 53->152 226 Antivirus detection for dropped file 53->226 228 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 53->228 230 Found direct / indirect Syscall (likely to bypass EDR) 53->230 154 build.netbazaar.lol 104.21.87.185 CLOUDFLARENET-CloudflareIncUS Canada 56->154 75 schtasks.exe 56->75         started        77 conhost.exe 58->77         started        79 conhost.exe 60->79         started        81 conhost.exe 62->81         started        83 conhost.exe 64->83         started        signatures19 process20 dnsIp21 142 rpc.sentio.xyz 104.26.12.205 CLOUDFLARENET-CloudflareIncUS Canada 66->142 110 C:\Windows\Temp\oeoajqda.sys, PE32+ 66->110 dropped 180 Suspicious powershell command line found 66->180 182 Protects its processes via BreakOnTermination flag 66->182 184 Found strings related to Crypto-Mining 66->184 186 8 other signatures 66->186 85 powershell.exe 66->85         started        88 powershell.exe 66->88         started        90 sc.exe 66->90         started        94 16 other processes 66->94 92 conhost.exe 75->92         started        file22 signatures23 process24 signatures25 204 Found many strings related to Crypto-Wallets (likely being stolen) 85->204 206 Loading BitLocker PowerShell Module 85->206 96 conhost.exe 85->96         started        98 conhost.exe 88->98         started        100 conhost.exe 90->100         started        102 conhost.exe 94->102         started        104 conhost.exe 94->104         started        106 conhost.exe 94->106         started        108 13 other processes 94->108 process26
Verdict:
Malware
YARA:
6 match(es)
Tags:
AutoIt CAB:COMPRESSION:LZX Decompiled Executable PDB Path PE (Portable Executable) PE File Layout PE Memory-Mapped (Dump) Suspect Win 64 Exe x64
Threat name:
Win64.Trojan.Malgent
Status:
Malicious
First seen:
2026-07-30 08:18:46 UTC
File Type:
PE+ (Exe)
Extracted files:
44
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Executes dropped EXE
Unpacked files
SH256 hash:
9b4fc704f7a53929ab614c2fc68bb63b85f901043375914a4e92cd0a8d32d643
MD5 hash:
55086caf39129a111ae656fed7976469
SHA1 hash:
b88ab0fbf814ed90523ae152caff3046f5863e66
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:Suspicious_Process
Author:Security Research Team
Description:Suspicious process creation
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments