๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a3cbf3a4455e38c93be71801901efe4567babaa3a574bd34ccc018a7c7f6f156. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 3


Intelligence 3 IOCs YARA 9 File information Comments

SHA256 hash: a3cbf3a4455e38c93be71801901efe4567babaa3a574bd34ccc018a7c7f6f156
SHA3-384 hash: 76108d04ad31bc4b2739fde98f3896aa3a84966409b7b121cce808c8d54ed52f19064317c200dfab4875535204cb2da2
SHA1 hash: c560e93513d9468df3b3949ec616be908a30b9ce
MD5 hash: 5e3fc8ec13677a5ae2ee776145cb6619
humanhash: stream-virginia-nineteen-charlie
File name:ยซ๐š๐šŽ๐šŠ๐š๐šข๐šˆ๐š๐™ต๐š’๐š•๐šŽ๐™ฝ๐š˜๐š†ยปยปยป4405ยป.7z
Download: download sample
Signature ACRStealer
File size:7'844'757 bytes
First seen:2025-10-25 15:19:53 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
Note:This file is a password protected archive. The password is: 4405
ssdeep 196608:EIZAeUMHG7VaBKzKJtyCC5payE/+25+fyeTr0pv:EIq5SsQBKzuZC5payOh5+LTrc
TLSH T1708633CDA3FEB05777546BB22E73E170850C001591EA381B2B558D5ABA0D86CE3DDEB2
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:74a65b 7z ACRStealer Amadey HIjackLoader IDATLoader pw-4405


Avatar
iamaachum
https://cludchpfile.click/ => https://mega.nz/file/TVMhQbQC#4vIi5PQZh2vwkXuS7r6oYJ9GryoZ1PBlHG7NSpsDpdU

Amadey Botnet: 74a65b
Amadey C2: http://mi.overlapsnowbound.com/kaWt2QXfpPueNM/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
ES ES
File Archive Information

This file archive contains 36 file(s), sorted by their relevance:

File name:Setup.exe
File size:35'408 bytes
SHA256 hash: 5d11218f67cfe78347280b0e1a06ade63c890ac78f970f57b0200ff5be8aa77c
MD5 hash: 4a8e1e703d538aa882b235ca98802b0c
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature ACRStealer
File name:NvStWiz.prx
File size:442'680 bytes
SHA256 hash: c2ad5bd189df04b39be18dec5cd251cf79b066010706ad26d99df7e49fd07762
MD5 hash: 9e82e3b658393bed3f7e4f090df1fbe7
MIME type:application/x-dosexec
Signature ACRStealer
File name:tradingnetworkingsockets.dll
File size:4'249'928 bytes
SHA256 hash: fc4a65ff603bf1f4bfe323de1866145ae1e006aa656799fd134dfa63d92d47c1
MD5 hash: 3cf26ce759c5e261fe3ecc6451b8b08e
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature ACRStealer
File name:opengl64.dll
File size:18'578'896 bytes
SHA256 hash: dd575f3c64382193610815909bd2c52490244ecbbb9bba6eef5fe4f0bb43bb4d
MD5 hash: 0a84667145e7efef026c888d4b768126
MIME type:application/x-dosexec
Signature ACRStealer
File name:TE.Host.dll
File size:391'232 bytes
SHA256 hash: 2a9af756333a415d7cd798eb87ea4a17e9c132b17051404e5e7076cab63f24bd
MD5 hash: 465f473d45beef730c636dbc6cd3493d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature ACRStealer
File name:TE.Loaders.dll
File size:494'672 bytes
SHA256 hash: a314743474564328a2610beb59413f7540487da3bf36380fb81e1a34d7c3670a
MD5 hash: ccfc9ff249250b3bf2163769e079bc78
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature ACRStealer
File name:Wex.Communication.dll
File size:399'424 bytes
SHA256 hash: a2bb6bd64eac312f0bd5d0ecc51c87ad55a44420ce9a9e26810192acc78da4b3
MD5 hash: e7e711b85ef0e0fba0cc8d48f98add32
MIME type:application/x-dosexec
Signature ACRStealer
File name:Atfrog.fc
File size:11'417 bytes
SHA256 hash: 81b3faffcebacf7916413ed42b33eebcb643d825cd5ec3f14e5e7358d2845be5
MD5 hash: f028fcff9963b2679dda4bf0519b6a2c
MIME type:application/octet-stream
Signature ACRStealer
File name:trading_api64.dll
File size:289'568 bytes
SHA256 hash: f1eb582e607a1e43cdb1654bfb7cb29ad46f6728b3fb89a14f7727e0e8daab69
MD5 hash: 2bca4e2c047ec969cb3cff277e7fc184
MIME type:application/x-dosexec
Signature ACRStealer
File name:Drourtnefiem.xw
File size:753'866 bytes
SHA256 hash: 51363a341b5e275cf479e7ee431b0a77f77f8fac342e7d5ad642c864447d1b64
MD5 hash: 145ef2397e32cd6ed76a855ee1ef8ea7
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature ACRStealer
File name:TE.WinRT.dll
File size:217'664 bytes
SHA256 hash: ef55c3d46b01b6ea9da5f87198849a9304a551a17f9d318ecd8aec0f93b620f6
MD5 hash: 674d03c68f6e4956747aa0403261cce4
MIME type:application/x-dosexec
Signature ACRStealer
File name:ks_tyres.ini
File size:10'077 bytes
SHA256 hash: 894d3c57598ecb22c769cc3ea8219859a95e22740e72394a474012ea2119b3d9
MD5 hash: 47f6571c7884da6c743551ac724186d4
MIME type:text/plain
Signature ACRStealer
File name:TE.Common.dll
File size:615'504 bytes
SHA256 hash: 7329a448d002060bc13a1caea1f88681cf9c75b0092b8e918fda901dc3e0ee75
MD5 hash: 37b7eee9838570894da2f69da26ebe6f
MIME type:application/x-dosexec
Signature ACRStealer
File name:config.prx
File size:373'656 bytes
SHA256 hash: 7fa86147035627bae39576bcbe619d045e94a48c4db8ca131968c20bb4de4a36
MD5 hash: 14934caca84d5fe0288f27efb31dcbf8
MIME type:application/x-dosexec
Signature ACRStealer
File name:Wex.Common.dll
File size:494'632 bytes
SHA256 hash: 0474a08a863958851ddc7fd826675ec7a176d6b095f25a00ce8445f74422364d
MD5 hash: d06e01dea072bf9d290ccb91073c838d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature ACRStealer
File name:Wex.Logger.dll
File size:625'216 bytes
SHA256 hash: 9ddb0f0db0aae8f137f293769b3febbba7625912e04ef6de4b672607cb40d5fe
MD5 hash: 842d407fdcd6f3d961395d8e7115589e
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature ACRStealer
File name:Conduit.Broker.dll
File size:510'544 bytes
SHA256 hash: b019dc9fd9132ff113a7e572819df386446744e7f800c8aaa4049fc4ec2b5aaf
MD5 hash: 30213c8ffae77c8bfe947660949048b6
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
infosteal
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive SFX 7z
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

7z a3cbf3a4455e38c93be71801901efe4567babaa3a574bd34ccc018a7c7f6f156

(this sample)

  
Delivery method
Distributed via web download

Comments