🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3e2a50c8e6851a103beb60f105870dcc3aaab291bd321a2a489b9c77d167b93. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 6


Intelligence 6 IOCs YARA 45 File information Comments

SHA256 hash: d3e2a50c8e6851a103beb60f105870dcc3aaab291bd321a2a489b9c77d167b93
SHA3-384 hash: e3fa87c799816548124aeac681f592f0ab781a63e5f8acb1404686537a1c30fb2ce185e48eeafda00b7e8ecd4c991f60
SHA1 hash: 1d6299f7e492f8b46caf74b2447b962d560d11fa
MD5 hash: 94b06989a68ef12a32dfcb0cc4655a81
humanhash: missouri-timing-nuts-spaghetti
File name:SETUP.zip
Download: download sample
Signature ACRStealer
File size:11'024'617 bytes
First seen:2025-09-17 18:15:36 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:2nm/FR4odDtO+WfOEv5eRSPyWtO9UKsybSoeryHofkx6XI3WG9e7NdO3NC7yxFhG:2m/IyO+tYQRYmaKNSMHikx6XI3WrBqWJ
TLSH T1FDB63307D5D04CEBE4DAE821B486380B59F9330CDE40945AB37B2F5678E4D3A0A75E9B
Magika zip
Reporter aachum
Tags:4e7b51 5-223-78-197 ACRStealer Amadey HIjackLoader IDATLoader zip


Avatar
iamaachum
https://enliscotie.cfd/?pub_id=12&key=aTo0pg2xh59cZQCvXbRj3mGktWIFHd7P48DNU1MSurfq6EA&site_id=22&data=hDokqd9yp4wvmiWQ1gNT => https://mega.nz/file/mbwGzCbL#q5Nc8NyYTB7qk8HJygbSyzVhudSUpI1-PYdGhM5zf2c

ACRStealer C2: 5.223.78.197

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
ES ES
File Archive Information

This file archive contains 45 file(s), sorted by their relevance:

File name:Setup.exe
File size:5'890'608 bytes
SHA256 hash: 14d140999ab5d2ab903ddf1aedda4d868be68db054424c7fad70b8927b32a145
MD5 hash: bd61566af089cacebdd1b4c41bfa4e85
MIME type:application/x-dosexec
Signature ACRStealer
File name:madExcept_.bpl
File size:445'440 bytes
SHA256 hash: f700ab8251ee590cb5a22e242bde3d8b7c62288278c0c051352ccc99b56ace4e
MD5 hash: 9e5f266f5b7c8771a2a25dcf5fc23873
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-2-0.dll
File size:18'384 bytes
SHA256 hash: 9ac63682e03d55a5d18405d336634af080dd0003b565d12a39d6d71aaa989f48
MD5 hash: 659e4febc208545a2e23c0c8b881a30d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-timezone-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: a108a8f20ded00e742a1f818ef00eb425990b6b24a2bcd060dea4d7f06d3f165
MD5 hash: 69df2cce4528c9e38d04a461ba1f992b
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-profile-l1-1-0.dll
File size:17'360 bytes
SHA256 hash: d00a0edace14715bf79dbd17b715d8a74a2300f0adb1f3fc137edfb7074c9b0a
MD5 hash: 6ee66dca31c5cce57740d677c85b4ce7
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-process-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 542a22540cdb7df46d957a0208d50507916f7c737bea833931239d56ebe8d68c
MD5 hash: 66f4e530a19ed2f6862b5ce946437875
MIME type:application/x-dosexec
Signature ACRStealer
File name:NvStWiz.prx
File size:442'680 bytes
SHA256 hash: c2ad5bd189df04b39be18dec5cd251cf79b066010706ad26d99df7e49fd07762
MD5 hash: 9e82e3b658393bed3f7e4f090df1fbe7
MIME type:application/x-dosexec
Signature ACRStealer
File name:PowerMgr.dll
File size:74'240 bytes
SHA256 hash: 461a9122a5c3a63644d005caa601cf9e4b7e5ef6f852e8767e398f39486e4e34
MD5 hash: d0d3e744178eea35ddb3e55568eeedca
MIME type:application/x-dosexec
Signature ACRStealer
File name:libcrypto-1_1.dll
File size:1'734'656 bytes
SHA256 hash: 2cf28f824d1c452b63087a7434996c05e897c486a04299dd2d72ab8e9ff39a0a
MD5 hash: 439e9fb8d5e39b48bfaa4f2700f65b83
MIME type:application/x-dosexec
Signature ACRStealer
File name:tradingnetworkingsockets.dll
File size:4'249'928 bytes
SHA256 hash: fc4a65ff603bf1f4bfe323de1866145ae1e006aa656799fd134dfa63d92d47c1
MD5 hash: 3cf26ce759c5e261fe3ecc6451b8b08e
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-private-l1-1-0.dll
File size:70'608 bytes
SHA256 hash: 696c10112d8b86a46e5057cbd0bf40728e79c6bb49cda1f2c67fe45d0fc1258d
MD5 hash: ad8d9a6ea592a6c8a78c67a805cec952
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-heap-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 0166edfb23cfc77519c97862a538a69b5d805d6a17d6e235f46927af5c04b3c9
MD5 hash: 9c373c00ac3138233bdf1655c7be8e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-util-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 68bd9c086d210eb14e78f00988ba88ceaf9056c8f10746ab024990f8512a2296
MD5 hash: c6553959aecd5bac01c0673cfdf86b68
MIME type:application/x-dosexec
Signature ACRStealer
File name:sdassist.dll
File size:206'336 bytes
SHA256 hash: 4a79ad74e70700b8db6bf101023d70fcd5b1b28f0e28584ee93610a873263995
MD5 hash: d76d18c5d897b043827ff03739b8298c
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-synch-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 8bb38a7a59fbaa792b3d5f34f94580429588c8c592929cbd307afd5579762abc
MD5 hash: 979c67ba244e5328a1a2e588ff748e86
MIME type:application/x-dosexec
Signature ACRStealer
File name:Register.dll
File size:1'483'312 bytes
SHA256 hash: 0408ee9513a32d5c5c1495e2ee3dcf43f02533cea770ab1f07e1ab0167f4067b
MD5 hash: d4e9244aed9d8ffc18f7d928f2e520c4
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-math-l1-1-0.dll
File size:27'088 bytes
SHA256 hash: c7115159babdaa1f52e478e67b4e612da2332fda4e4036999b29425fe303b6e8
MD5 hash: bc418a3461c5fdfa1a0d75f7e03d08a7
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-rtlsupport-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: d11093fdc1d5c9213b9b2886ce91db3ded17ef8dae1615a8c7ffbc55b8e3f79b
MD5 hash: 0069fd29263c0dd90314c48bbce852ef
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-filesystem-l1-1-0.dll
File size:19'920 bytes
SHA256 hash: 85b1b189ce9e3c6f4d2efdd4cd82b0807f681bea2d28851caaf545990de99000
MD5 hash: 14f407d94c77b1b0039ae2c89b07a2ff
MIME type:application/x-dosexec
Signature ACRStealer
File name:Temperature.dll
File size:177'664 bytes
SHA256 hash: d987a17b4566602232353909027fa07ac5bf2c38f0613b24873e84fcc5e1d336
MD5 hash: 3747108570b8433d047a7e1208fda541
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-conio-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 4aeeae0ac9f6c1b0b8835067ea3b7fc429f353565f18de7858f4ea5d6f72072e
MD5 hash: 7190cbfad2d7773d3b88ccc25533a651
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-processthreads-l1-1-1.dll
File size:18'384 bytes
SHA256 hash: e5ea2c21fb225090f7d0db6c6990d67b1558d8e834e86513bc8ba7a43c4e7b36
MD5 hash: 29001f316ccfc800e2246743df9b15b3
MIME type:application/x-dosexec
Signature ACRStealer
File name:vcl120.bpl
File size:2'014'720 bytes
SHA256 hash: 859d84044efc9b130c639db1c9e65250546606ffd7e3f27f491099e56fbca97c
MD5 hash: d5145c203ad9d94a13416b1e5400ab2d
MIME type:application/x-dosexec
Signature ACRStealer
File name:trading_api64.dll
File size:289'568 bytes
SHA256 hash: f1eb582e607a1e43cdb1654bfb7cb29ad46f6728b3fb89a14f7727e0e8daab69
MD5 hash: 2bca4e2c047ec969cb3cff277e7fc184
MIME type:application/x-dosexec
Signature ACRStealer
File name:rtl120.bpl
File size:1'115'136 bytes
SHA256 hash: 9d299887fb4a886be03f11a86af0d1021a2331ab0283c90ba6d790fa366d3767
MD5 hash: 886bcdd81bbce31fa03c23e78f11158c
MIME type:application/x-dosexec
Signature ACRStealer
File name:sqlite3.dll
File size:927'104 bytes
SHA256 hash: 622243b663cb4beef8ac22184e72a15e4593b3591804188114385b00950a7eb7
MD5 hash: 3fcc5348556331c365025ac57dfbcb1a
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-sysinfo-l1-1-0.dll
File size:18'896 bytes
SHA256 hash: 1fe918979f1653d63bb713d4716910d192cd09f50017a6ecb4ce026ed6285df9
MD5 hash: cef4b9f680faae322170b961a3421c5b
MIME type:application/x-dosexec
Signature ACRStealer
File name:Scan.dll
File size:1'026'560 bytes
SHA256 hash: 313778d51081f38feb3b9ea5279f941b4793291a1842306022d329242a57e0d7
MD5 hash: 1fbb754a64f4c48984f47fc0532799d4
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-convert-l1-1-0.dll
File size:21'968 bytes
SHA256 hash: 77b69e829bdc26c7b2474be6b8a2382345b2957e23046897e40992a8157a7ba1
MD5 hash: 3e415147ccd7c712618868bdd7a200cd
MIME type:application/x-dosexec
Signature ACRStealer
File name:madBasic_.bpl
File size:214'016 bytes
SHA256 hash: 542777a1beae1000bf1382230e99aebb0b232e6fd1e750a2ab66ebfa8c55212d
MD5 hash: 4bc92439d20afa8727d27382c23042ed
MIME type:application/x-dosexec
Signature ACRStealer
File name:HardwareLib.dll
File size:189'952 bytes
SHA256 hash: 4e5f1f42f90316819b9fe431722c5cc8c0a91d90e0fea87e580f17629e088a9a
MD5 hash: 022568111d51b5dbb92c0ab0872b380c
MIME type:application/x-dosexec
Signature ACRStealer
File name:ks_tyres.ini
File size:10'077 bytes
SHA256 hash: 894d3c57598ecb22c769cc3ea8219859a95e22740e72394a474012ea2119b3d9
MD5 hash: 47f6571c7884da6c743551ac724186d4
MIME type:text/plain
Signature ACRStealer
File name:config.prx
File size:373'656 bytes
SHA256 hash: 7fa86147035627bae39576bcbe619d045e94a48c4db8ca131968c20bb4de4a36
MD5 hash: 14934caca84d5fe0288f27efb31dcbf8
MIME type:application/x-dosexec
Signature ACRStealer
File name:vclx120.bpl
File size:225'280 bytes
SHA256 hash: 36f599a8ff2bb6246f895f92a3bf2611a69c2590d5ac28d1160f7a34fe33a3fd
MD5 hash: 79c930429a1b86933c1ca4346ab74d34
MIME type:application/x-dosexec
Signature ACRStealer
File name:madDisAsm_.bpl
File size:62'976 bytes
SHA256 hash: 3c930bbc232dc6e3c06b77a372431197ad31f4e75f2f68b9547fc29b015d9e49
MD5 hash: 3f02eac260ab175a46849c2b70caf483
MIME type:application/x-dosexec
Signature ACRStealer
File name:libssl-1_1.dll
File size:361'472 bytes
SHA256 hash: fcc0e468e0ea8ee56231f5678e527c7d2312fcc5dfddd7fbeb71896206500b47
MD5 hash: 473f224dd928b93370e3e12a12d78ce7
MIME type:application/x-dosexec
Signature ACRStealer
File name:Jaettiet.pj
File size:31'022 bytes
SHA256 hash: 834ae8883d16f3da13e8826f012472ff0df5eaa0c8f5ebed42f01fc9f0c88ff0
MD5 hash: a7398a33f405117bc6fd845f993184b3
MIME type:application/octet-stream
Signature ACRStealer
File name:Gied.cti
File size:1'024'598 bytes
SHA256 hash: 11c4163dcecbdcac32bf584a157181871b904306cca47bd7e29bbc28f19dcb62
MD5 hash: ff8cdcad9cf744c1f4de40ecd9d91c49
MIME type:application/octet-stream
Signature ACRStealer
File name:api-ms-win-crt-locale-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: f16447b5fc7fe6fb8a6699a3cef1b2b8ba92d408579bcc272d3dd76acd801e2a
MD5 hash: c5d747f96237b6e9aa85c58745d30c80
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-environment-l1-1-0.dll
File size:18'384 bytes
SHA256 hash: 6c9c0dc7b36afe07dfb07dd373fc757ff25df4793e6384d7a6021471a474f0b9
MD5 hash: ad0cbb9978fcf60d9e9ca45de6a28d30
MIME type:application/x-dosexec
Signature ACRStealer
File name:datastate.dll
File size:76'288 bytes
SHA256 hash: 6d33107ce562e7fa41a2cd7a48b4c8ab49cc5ee16af9fadcb65277cdca27c4e3
MD5 hash: a1b5a4d4d8e027c056b6b6a2a5a22080
MIME type:application/x-dosexec
Signature ACRStealer
File name:dataexchange.dll
File size:78'336 bytes
SHA256 hash: 13dd748913c226f4929af229f755230724adbba5ced7c11b83bc918f8294b5da
MD5 hash: 1299a7fd5e65e32a7dde8af89e4db61d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-core-string-l1-1-0.dll
File size:17'872 bytes
SHA256 hash: 3807db7acf1b40c797e4d4c14a12c3806346ae56b25e205e600be3e635c18d4f
MD5 hash: 2e5c29fc652f432b89a1afe187736c4d
MIME type:application/x-dosexec
Signature ACRStealer
File name:PluginHelper.dll
File size:137'728 bytes
SHA256 hash: 3b123f1fea7f38de527bca6dc51b9a922a7189a72441b48a39743063fb131148
MD5 hash: ddc1cc25830c2afaaa64d6bd784fb26d
MIME type:application/x-dosexec
Signature ACRStealer
File name:api-ms-win-crt-multibyte-l1-1-0.dll
File size:26'064 bytes
SHA256 hash: c6b4e1d903b3cc83bfaffbe4e82eee634cff8f97f12217caa45b464ddc4e1455
MD5 hash: 9e9c6f83a015029808f5257f7b7e39c6
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.9%
Tags:
downloader dropper virus
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
expired-cert fingerprint microsoft_visual_cc overlay packed signed
Verdict:
Malicious
File Type:
zip
First seen:
2025-09-17T13:04:00Z UTC
Last seen:
2025-09-17T13:04:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-17 18:17:40 UTC
File Type:
Binary (Archive)
Extracted files:
361
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Borland
Author:malware-lu
Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:ffdroider
Author:Michelle Khalil
Description:This rule detects unpacked ffdroider stealer malware samples.
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:INDICATOR_KB_CERT_62e745e92165213c971f5c490aea12a5
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/
Rule name:WHIRLPOOL_Constants
Author:phoul (@phoul)
Description:Look for WhirlPool constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip d3e2a50c8e6851a103beb60f105870dcc3aaab291bd321a2a489b9c77d167b93

(this sample)

  
Delivery method
Distributed via web download

Comments