🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c283382075b792e2dc4cddcc637618944c2b89b50b93bd91f345ed7c41f3a28a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 3


Intelligence 3 IOCs YARA 1 File information Comments

SHA256 hash: c283382075b792e2dc4cddcc637618944c2b89b50b93bd91f345ed7c41f3a28a
SHA3-384 hash: 8340061507b9f56fd2b2b9558d41f8e076a06f4c053738804357a4e810c8739ae508ae78d18a2c17a2d9befc2bf537fc
SHA1 hash: 18cf51588fcbcf49ef4615d95226157afb023d02
MD5 hash: b891a531fc937f2cd2fed17a516afc58
humanhash: venus-blue-violet-rugby
File name:Setup.rar
Download: download sample
Signature ACRStealer
File size:19'297'293 bytes
First seen:2025-11-04 14:52:34 UTC
Last seen:Never
File type: rar
MIME type:application/x-7z-compressed
ssdeep 393216:t+4WlA0hpSt7eB5Xc2+J0P2KBbe0MMW5/MkAx+LA0MYacMiLBmp:t+HPrMCB5XR+JQ2u1MX5/hAYFMYaOLBa
TLSH T17F17334DF9066B098321D9770E4B95243DFB42FFAF82AF13717AA8575EC04CAB42944B
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter aachum
Tags:2265ca 65-109-162-230 ACRStealer Amadey file-pumped rar


Avatar
iamaachum
https://disk.yandex.com/d/gjkODS8j2FHGUw

ACRStealer C2: 65.109.162.230
Amadey Botnet: 2265ca
Amadey C2: mi.huffproofs.com

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
ES ES
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Setup.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:740'648'192 bytes
SHA256 hash: 2d83db8430c3f1518fd3e756a650154dd0e6fa167b6e1be8426c60d29d9d6777
MD5 hash: bbe4a1d6f5d7ae97b0719c33f4d623a1
De-pumped file size:512'556'544 bytes (Vs. original size of 740'648'192 bytes)
De-pumped SHA256 hash: 76b8cc640d450bc4fe8630aa178cc64a3271e3c7a3b6df54a225742d277288dc
De-pumped MD5 hash: 6cabb21c7047a841121b8ff43c8f61fd
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Gathering data
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
7z Archive Executable PDB Path PE (Portable Executable) PE File Layout SFX 7z
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

rar c283382075b792e2dc4cddcc637618944c2b89b50b93bd91f345ed7c41f3a28a

(this sample)

  
Delivery method
Distributed via web download

Comments