🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4c1d4e2524b4955784c61bf748346012e7546f8b1c3559f0815040687ed1069. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ACRStealer


Vendor detections: 6


Intelligence 6 IOCs YARA 12 File information Comments

SHA256 hash: e4c1d4e2524b4955784c61bf748346012e7546f8b1c3559f0815040687ed1069
SHA3-384 hash: 8c1b39e04d1a0260dcc1c1614f99d861007ebd8960bdbdafdc9b992dcc5e51b749792f37f1503803b142c5effb65475b
SHA1 hash: 1ba70b32bc5a6c763362ff8d1b2aff0ebfd712f1
MD5 hash: 69b4b40525cf20a70744f4d187bef90f
humanhash: black-harry-high-aspen
File name:payload_decrypted.zip
Download: download sample
Signature ACRStealer
File size:15'932'228 bytes
First seen:2026-09-12 13:46:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:rkwDtLsuA6uh+jtr0Z5zZ3wwxZC8kJ/Js:rHZA6faNZReJ/Js
TLSH T1ACF69D56B67840D5C0B6C0B885E69647F3B138140B315BDB32AE866E6F37BE01E7B721
TrID 72.4% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
27.5% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter aachum
Tags:ACRStealer dropped-by-RenPyLoader HIjackLoader IDATLoader login-nimbusforge-cc zip


Avatar
iamaachum
https://cloud-file-wgry.vvm4xwsy9.buzz/

ACRStealer C2: login.nimbusforge.cc

Intelligence


File Origin
# of uploads :
1
# of downloads :
111
Origin country :
ES ES
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:sessiondef59.cfg
File size:1'451'206 bytes
SHA256 hash: 2ebd394dd1eeba35df2a5174fea21df58cadc92a4debfd10d673b9ace3529d14
MD5 hash: 3e00e1c25ace2867a9eefaa67bee3f16
MIME type:application/octet-stream
Signature ACRStealer
File name:vcruntime140_1.dll
File size:49'744 bytes
SHA256 hash: 0e560532e721b6938dafe4055eedd0251ba5eb5994cd96937cebbcf16a7ddae5
MD5 hash: 7e986e7469d9ab3b1138353418da1793
MIME type:application/x-dosexec
Signature ACRStealer
File name:Xhe9Psl7E.exe
File size:5'566'168 bytes
SHA256 hash: 583a6e6e00730d23b0ecf0e801144cf06d27053a897524214f0aecbe967096f2
MD5 hash: a61513d897aa89620f8ee94866724696
MIME type:application/x-dosexec
Signature ACRStealer
File name:mesh_base.map
File size:16'968 bytes
SHA256 hash: b3d7486928b5070a07784039e064d7e6ed0a6ba7f5331ad374db3c87e1b3c026
MD5 hash: 2a68aab5c14078bc81396805177acfb0
MIME type:application/octet-stream
Signature ACRStealer
File name:msvcp_win.dll
File size:637'880 bytes
SHA256 hash: 08f2fe38501a88a7d3c13976733c2ca08b5597c3328d51fa1f5f5d8474c33ecf
MD5 hash: 26e256e40cdb3b9cfe599653c8708cb0
MIME type:application/x-dosexec
Signature ACRStealer
File name:HeadTrackerLib.dll
File size:6'057'984 bytes
SHA256 hash: 801eea56aa6750293bea26ee05fffd5ff9bfee90929ece6fb137c8029f2c57e9
MD5 hash: f9c919d1142673935421d2276b736131
MIME type:application/x-dosexec
Signature ACRStealer
File name:vcruntime140.dll
File size:119'888 bytes
SHA256 hash: 642ae52687a7a6bfb03d0b20dc7e07f4b11ceca634f7eb7ba184d6711ab51a51
MD5 hash: c22ab531881b21277ba168e6f311d225
MIME type:application/x-dosexec
Signature ACRStealer
File name:ucrtbase.dll
File size:1'133'624 bytes
SHA256 hash: d93ce42cd625510b2355de086bcd19e2c11307ccade7bad62b09c7f340a866ba
MD5 hash: 24ebedc58aa4ff23043bf79b05d267d4
MIME type:application/x-dosexec
Signature ACRStealer
File name:concrt140.dll
File size:322'640 bytes
SHA256 hash: 3bfe7958b6c5cc0150927e6da0551829b8e3e1a3a8bb446adbf64f7f84751f74
MD5 hash: 7e98e42b33707e865c1dc8f4099118db
MIME type:application/x-dosexec
Signature ACRStealer
File name:msvcp140.dll
File size:575'056 bytes
SHA256 hash: 7b8a6f283884e6448559dcf510b00c1a885bfb8e598ea05cd2c290c874657326
MD5 hash: 6c3ad90ee8d03a4ce68dbb34b0d72b1e
MIME type:application/x-dosexec
Signature ACRStealer
Vendor Threat Intelligence
Malware configuration found for:
HijackLoader
Details
Verdict:
Unknown
Threat level:
n/a  -.1.0/10
Confidence:
100%
Tags:
anti-debug crypto expired-cert fingerprint microsoft_visual_cc signed
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout PE Memory-Mapped (Dump) SVG Zip Archive
Threat name:
Binary.Trojan.Rugmi
Status:
Malicious
First seen:
2026-09-12 13:47:35 UTC
File Type:
Binary (Archive)
Extracted files:
37
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:acrstealer family:hijackloader discovery loader spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Malware Config
C2 Extraction:
login.nimbusforge.cc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HUNTING_SUSP_TLS_SECTION
Author:chaosphere
Description:Detect PE files with .tls section that can be used for anti-debugging
Reference:Practical Malware Analysis - Chapter 16
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

ACRStealer

zip e4c1d4e2524b4955784c61bf748346012e7546f8b1c3559f0815040687ed1069

(this sample)

  
Delivery method
Distributed via web download

Comments