MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a6b08f633ad63cbe5f98abb2269cdecdd85c7c93255ee784f14e871af33d7d35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 13


Intelligence 13 IOCs YARA 5 File information Comments

SHA256 hash: a6b08f633ad63cbe5f98abb2269cdecdd85c7c93255ee784f14e871af33d7d35
SHA3-384 hash: d0047ee7f6684ec0f2864120f56dac2861456c63a883eac0954478155a6c7dfa6be27d5829be31fd1a7ee73a517fc917
SHA1 hash: 7885b0bfff6a373b82c229a5e8d9e2b20ae44e7f
MD5 hash: 7f4ce93930e8a11edbc5f4c541bacd1a
humanhash: mountain-lemon-kitten-one
File name:Genesis.exe
Download: download sample
Signature ACRStealer
File size:1'676'288 bytes
First seen:2026-07-30 08:58:46 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 013c74198fc6e42dcf33737d6c40c012 (11 x RedLineStealer, 8 x Stealc, 4 x NanoCore)
ssdeep 24576:FXTV5JftJdWXSXgzsJohbSwxxmhROMcCGfr5tv6mEpvttGtzEif2qK4+ptR:xJfIXSXgzsKhbzMcCGjmtaCd4+p
TLSH T14C7523E253E410AAE4FD977948FA8323C731FC4557B4968F2314D9CA0F226D47A307AA
TrID 89.3% (.EXE) Win32 MS Cabinet Self-Extractor (WExtract stub) (303567/2/11)
4.8% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
1.9% (.EXE) Win64 Executable (generic) (6522/11/2)
1.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.6% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 6169dcd4b2f24a4e (1 x ACRStealer)
Reporter burger
Tags:ACRStealer exe

Intelligence


File Origin
# of uploads :
1
# of downloads :
193
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
Archives AutoIt
Details
Malware family:
n/a
ID:
1
File name:
https://genesis-cloud.cc/product.html?product=Seliware-Executor
Verdict:
Malicious activity
Analysis date:
2026-07-30 01:08:32 UTC
Tags:
fingerprinting fileshare websocket phishing autoit generic

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Creating a process with a hidden window
Creating a window
DNS request
Unauthorized injection to a recently created process
Deleting a recently created file
Unauthorized injection to a recently created process by context flags manipulation
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug autoit CAB expired-cert explorer fingerprint installer installer installer-heuristic keylogger lolbin microsoft_visual_cc packed reconnaissance rundll32 runonce sfx
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-29T14:25:00Z UTC
Last seen:
2026-08-01T00:27:00Z UTC
Hits:
~100
Detections:
BSS:Trojan.Win32.Generic Backdoor.Win32.Agent.myxhxm Backdoor.Agent.UDP.C&C
Result
Threat name:
ACR Stealer, Xmrig
Detection:
malicious
Classification:
evad.troj.spyw.mine
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Creates / moves files in alternative data streams (ADS)
Creates an undocumented autostart registry key
Found direct / indirect Syscall (likely to bypass EDR)
Found evasive API chain (may stop execution after checking mutex)
Found many strings related to Crypto-Wallets (likely being stolen)
Found strings related to Crypto-Mining
Injects a PE file into a foreign processes
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Modifies windows update settings
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
PE file contains section with special chars
Performs DNS queries to domains with low reputation
Protects its processes via BreakOnTermination flag
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Sample is not signed and drops a device driver
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Schedule system process
Sigma detected: Suspicious Script Execution From Temp Folder
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Unusual module load detection (module proxying)
Uses cmd line tools excessively to alter registry or file data
Uses nslookup.exe to query domains
Uses schtasks.exe or at.exe to add and modify task schedules
Verifies if a H.264 Video Encoder exists (likely to detect the VM)
Writes to foreign memory regions
Yara detected ACR Stealer
Yara detected Xmrig cryptocurrency miner
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1950014 Sample: Genesis.exe Startdate: 30/07/2026 Architecture: WINDOWS Score: 100 136 serve.eastpeak.xyz 2->136 138 route.techquarter.xyz 2->138 140 9 other IPs or domains 2->140 172 Suricata IDS alerts for network traffic 2->172 174 Malicious sample detected (through community Yara rule) 2->174 176 Antivirus detection for URL or domain 2->176 180 10 other signatures 2->180 13 Genesis.exe 4 2->13         started        16 LockAppHost14a02b.exe 2->16         started        19 UsoClient34ed49.exe 2->19         started        22 2 other processes 2->22 signatures3 178 Performs DNS queries to domains with low reputation 138->178 process4 dnsIp5 126 C:\Users\user\AppData\Local\...\AutoIt3.exe, PE32+ 13->126 dropped 24 AutoIt3.exe 13->24         started        162 Antivirus detection for dropped file 16->162 164 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 16->164 166 Uses nslookup.exe to query domains 16->166 170 4 other signatures 16->170 142 polygon-bor-rpc.publicnode.com 104.20.24.117 CLOUDFLARENET-CloudflareIncUS Canada 19->142 168 Found direct / indirect Syscall (likely to bypass EDR) 19->168 27 schtasks.exe 19->27         started        file6 signatures7 process8 signatures9 210 Found evasive API chain (may stop execution after checking mutex) 24->210 212 Modifies the context of a thread in another process (thread injection) 24->212 214 Tries to detect virtualization through RDTSC time measurements 24->214 216 3 other signatures 24->216 29 AutoIt3.exe 82 24->29         started        34 conhost.exe 27->34         started        process10 dnsIp11 158 193.233.75.215, 49862, 80 DHOST-ASRU Germany 29->158 160 job.coast-space.lol 172.67.142.116, 443, 49860 CLOUDFLARENET-CloudflareIncUS Canada 29->160 128 C:\Users\user\AppData\...\y39exrqwmc.exe, PE32+ 29->128 dropped 130 C:\Users\user\AppData\...\o7cnd1bu6x.exe, PE32+ 29->130 dropped 132 C:\Users\user\AppData\...\4281laxorl.exe, PE32+ 29->132 dropped 134 2 other malicious files 29->134 dropped 218 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 29->218 220 Creates / moves files in alternative data streams (ADS) 29->220 222 Found many strings related to Crypto-Wallets (likely being stolen) 29->222 224 4 other signatures 29->224 36 o7cnd1bu6x.exe 98 29->36         started        41 4281laxorl.exe 29->41         started        43 0chq7p235h.exe 10 29->43         started        45 y39exrqwmc.exe 29->45         started        file12 signatures13 process14 dnsIp15 144 polygon.drpc.org 104.18.10.59 CLOUDFLARENET-CloudflareIncUS Canada 36->144 146 polygon-public.nodies.app 172.67.70.207 CLOUDFLARENET-CloudflareIncUS Canada 36->146 148 serve.eastpeak.xyz 172.67.161.115 CLOUDFLARENET-CloudflareIncUS Canada 36->148 112 C:\Users\...\SmartScreenHost27dac.exe (copy), PE32+ 36->112 dropped 194 Antivirus detection for dropped file 36->194 196 Multi AV Scanner detection for dropped file 36->196 198 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 36->198 208 5 other signatures 36->208 47 explorer.exe 36->47 injected 50 schtasks.exe 36->50         started        52 powershell.exe 36->52         started        114 C:\Users\user\...\MusNotificationce794c.exe, PE32+ 41->114 dropped 116 :x (copy), PE32+ 41->116 dropped 200 Creates / moves files in alternative data streams (ADS) 41->200 202 Creates an undocumented autostart registry key 41->202 204 Found direct / indirect Syscall (likely to bypass EDR) 41->204 54 MusNotificationce794c.exe 41->54         started        118 C:\Users\user\AppData\...\UsoClient34ed49.exe, PE32+ 43->118 dropped 120 :n (copy), PE32+ 43->120 dropped 206 Uses schtasks.exe or at.exe to add and modify task schedules 43->206 57 UsoClient34ed49.exe 33 43->57         started        59 schtasks.exe 1 43->59         started        122 C:\ProgramData\...\LockAppHost14a02b.exe, PE32+ 45->122 dropped 124 :r (copy), PE32+ 45->124 dropped 61 sc.exe 45->61         started        63 sc.exe 45->63         started        65 sc.exe 45->65         started        file16 signatures17 process18 dnsIp19 226 Uses nslookup.exe to query domains 47->226 67 nslookup.exe 47->67         started        71 conhost.exe 50->71         started        73 conhost.exe 52->73         started        150 poly.api.pocket.network 136.243.145.207 HETZNER-ASDE Germany 54->150 152 route.techquarter.xyz 104.21.46.61 CLOUDFLARENET-CloudflareIncUS Canada 54->152 228 Antivirus detection for dropped file 54->228 230 Multi AV Scanner detection for dropped file 54->230 232 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 54->232 154 polygon.gateway.tenderly.co 35.227.193.242 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 57->154 156 build.netbazaar.lol 172.67.145.154 CLOUDFLARENET-CloudflareIncUS Canada 57->156 234 Found direct / indirect Syscall (likely to bypass EDR) 57->234 75 schtasks.exe 57->75         started        77 conhost.exe 59->77         started        79 conhost.exe 61->79         started        81 conhost.exe 63->81         started        83 conhost.exe 65->83         started        signatures20 process21 file22 110 C:\Windows\Temp\oeoajqda.sys, PE32+ 67->110 dropped 182 Suspicious powershell command line found 67->182 184 Protects its processes via BreakOnTermination flag 67->184 186 Found strings related to Crypto-Mining 67->186 188 8 other signatures 67->188 85 powershell.exe 67->85         started        88 powershell.exe 67->88         started        90 sc.exe 67->90         started        94 15 other processes 67->94 92 conhost.exe 75->92         started        signatures23 process24 signatures25 190 Found many strings related to Crypto-Wallets (likely being stolen) 85->190 192 Loading BitLocker PowerShell Module 85->192 96 conhost.exe 85->96         started        98 conhost.exe 88->98         started        100 conhost.exe 90->100         started        102 conhost.exe 94->102         started        104 conhost.exe 94->104         started        106 conhost.exe 94->106         started        108 12 other processes 94->108 process26
Verdict:
Malware
YARA:
6 match(es)
Tags:
AutoIt CAB:COMPRESSION:LZX Decompiled Executable PDB Path PE (Portable Executable) PE File Layout Suspect Win 64 Exe x64
Threat name:
Win64.Trojan.Malgent
Status:
Malicious
First seen:
2026-07-29 23:07:14 UTC
File Type:
PE+ (Exe)
Extracted files:
48
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Executes dropped EXE
Unpacked files
SH256 hash:
a6b08f633ad63cbe5f98abb2269cdecdd85c7c93255ee784f14e871af33d7d35
MD5 hash:
7f4ce93930e8a11edbc5f4c541bacd1a
SHA1 hash:
7885b0bfff6a373b82c229a5e8d9e2b20ae44e7f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments