🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b0c019378317bd23a931b35d688d541098f1b5136e1e5c2c5387594f71ab7e46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b0c019378317bd23a931b35d688d541098f1b5136e1e5c2c5387594f71ab7e46
SHA3-384 hash: e6cad6000ba3fe3bced7dddc52db7b1063b1d1bcec36cfabd93c10fad5b3e41479656d80764b7da7f5bb2f0222642f99
SHA1 hash: e15f8be498fa6c9ba3035099d67cfcb9012282c9
MD5 hash: d51be91da598b5fe7f7d7be71056014f
humanhash: glucose-sweet-south-cardinal
File name:setup.zip
Download: download sample
Signature ACRStealer
File size:55'203'277 bytes
First seen:2025-11-04 14:39:37 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1572864:NekK8zYe/et5cf07jOjW7bV6U0OdgitGhriJ+P/ul0Tdb:NFKz+eTO07uiJ10HsGxO+PgA9
TLSH T1FEC733089F294FE3D539667356A9E71B69FDCF1B24C3C3871362E14529BA3AE8C75200
Magika zip
Reporter aachum
Tags:2265ca 46-224-18-100 ACRStealer Amadey file-pumped zip


Avatar
iamaachum
https://n78vzdib.cfd/ => https://mega.nz/file/mA1C3S7Q#caP0laGvfRzOyykuSJqL-jX2V1jRbVN30hTvQoi4gy0

ACRStealer C2: 46.224.18.100
Amadey Botnet: 2265ca
Amadey C2: http://mi.huffproofs.com/kaWt2QXfpPueNM/index.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
ES ES
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:setup.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:737'817'252 bytes
SHA256 hash: 9ff86a214f4588c03f51092aaf39e6e8b31604960d5e31bdd5d0b878d5401ce3
MD5 hash: afbb7f37fba979e7dfa5cbf49b4b11c1
De-pumped file size:512'339'968 bytes (Vs. original size of 737'817'252 bytes)
De-pumped SHA256 hash: 95495989c0f0d69537a343f850202c1fd3547baf72b5bba2b7d2b3b5eca15ddd
De-pumped MD5 hash: 1ff521244652cca76dff52ae8bfa1399
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
spawn hype sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug blackhole installer installer installer-heuristic invalid-signature large-file microsoft_visual_cc nsis signed
Gathering data
Result
Malware family:
acrstealer
Score:
  10/10
Tags:
family:acrstealer discovery execution spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Command and Scripting Interpreter: PowerShell
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Badlisted process makes network request
ACR stealer,GrMsk
Acrstealer family
Detects unpacked ACRstealer payload
Malware Config
Dropper Extraction:
http://87.120.219.26/CCZT7wMNnD29ie
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip b0c019378317bd23a931b35d688d541098f1b5136e1e5c2c5387594f71ab7e46

(this sample)

  
Delivery method
Distributed via web download

Comments