MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 16


Intelligence 16 IOCs YARA 3 File information Comments

SHA256 hash: 018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
SHA3-384 hash: c90f95b2a71379c9bbac4e63d4a1a23884484c673eda88be0ff360ad5bc70fce5d5aef0e6d3e729f05487e66a04bfdde
SHA1 hash: ce60ffc172f18ba31d8384ebff0b843ae2f82fe4
MD5 hash: 71527a93de96710a1c83c3083189e323
humanhash: oxygen-pasta-one-uncle
File name:lNX7Cz67b3bzA0J.exe
Download: download sample
Signature Stealc
File size:1'441'280 bytes
First seen:2026-07-23 08:10:22 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'123 x AgentTesla, 20'137 x Formbook, 12'362 x SnakeKeylogger)
ssdeep 24576:DW+YQDVIWZUdrjJX13CYgsKg/ZT9x/EUwKRiCa8WaL3qpkzVbUE:iVGIWZQt13u7gV9xplRiCaFabpVo
TLSH T13B65238193D98038C6A66B361ED5F27343B6ADB8B532C72A6FECBDDB75353058C01252
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 44302c2c70703002 (3 x RemusStealer, 1 x PhantomStealer, 1 x Stealc)
Reporter aachum
Tags:103-101-85-184 exe Stealc unluckytool-com


Avatar
iamaachum
https://gsmtoolpack.com/Setup.rar

Stealc C2:
103.101.85.184

Intelligence


File Origin
# of uploads :
1
# of downloads :
183
Origin country :
ES ES
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
https://tmpfiles.org/wfwV9x5KhqeL/get-install-222.exe
Verdict:
Malicious activity
Analysis date:
2026-07-20 14:04:22 UTC
Tags:
fingerprinting possible-phishing loader stealer remus ip-check evasion python powershell openssl tool

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Connection attempt
Sending an HTTP POST request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
formbook packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-17T16:58:00Z UTC
Last seen:
2026-07-23T11:59:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Found direct / indirect Syscall (likely to bypass EDR)
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.33 Win 32 Exe x86
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-21 04:06:00 UTC
AV detection:
22 of 36 (61.11%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:stealc discovery spyware stealer
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
SmartAssembly .NET packer
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Detects Stealc stealer Version 2
Family: Stealc
Unpacked files
SH256 hash:
018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
MD5 hash:
71527a93de96710a1c83c3083189e323
SHA1 hash:
ce60ffc172f18ba31d8384ebff0b843ae2f82fe4
SH256 hash:
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
MD5 hash:
a8480ece517b8367ca8418d7888f410d
SHA1 hash:
49802c5598b2e9d94229ae987d0ac47bbf8977ea
Detections:
win_stealc_auto
Parent samples :
84bd20bcb88426402c4a3c96d8012396f83387a84b7abc1a6e90c2babebb42bd
b91cebec72ba934cde8ee67e8c4135c8c558d8ff46a70d3fdca83d9c37dd377b
290e9e54d6ff86cb4afc7acbbf10a06ed10f3fe476768dc96129a2a715208330
abb513eaa060b22c139fef518ba9b45785acd317ea6e01a945df346c9564eff7
764936d39ec0d9e3e00e04db2d6d3acc61b6bf77412ddc67ce180d6fbf665f58
fb924e8cef93d0a4244790ba1e1a4ecaf1a93b19f8e816329cdd763b017df459
bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241
9a7c87d58a7ab1f2d99c5390d04c3875e41587b46f0632518e6108286ca45e2c
711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
0215f734867bd71c57ff5c524d8cc670be5b4f1861b2c390cf46d18784a53624
efe7eb517cc449cc7721c5c0acfb8cf454f28fdf2f37c08854aad4deefd7edc9
1217681270b058cb08ff0eef8aad93219db13db2162a528d99267a354a85e62a
0f97b6a0c25560d63a863ff043a9556cb730ed6c8b20916eac98e2b969ab5f48
b7060387c40d51ac08a6e7ce33226b02f975ccfdc8ffa95c7412110e4adbe855
d5cad85a993f432900438b0b241f62226f2709cc7d2a0ab6897f58009eb4d670
1188d1f47cfc3797e1eb004e531b11b7a191a21475d97226dfa607db380b650b
dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402
9fe5f01662010999236f92b351ef36a759a58421fa4bca630c17e35e8cf8e0d9
354d3dc2b8997764925d5c42ee1c87acb4ba0bdca257edb7a2e63f53a4678c5c
526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d
252653fff0e5c8ce66326b2f105dcb74a728c76d78991773e385fa580c0833cf
e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
80b64331aab73ae1cb476c6a1dbe804abf304fded3d52303a700524e8370c92b
018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
SH256 hash:
281f0a31109ba3566ae24aad9d51a96464ffc1d21e36b6b6772663df2f0faac0
MD5 hash:
dde879de3fd7eb5674e79b43c6f5722d
SHA1 hash:
63a6adfa2f3d970779f8f77c69c9da620b52f3e4
SH256 hash:
91f7aec039593fd4db2be2e82ffc6ec667746e972e1b9b23fc1a6a246bbaa660
MD5 hash:
a493fd51afb3ed5bc9c339c6d8f8aa2e
SHA1 hash:
9efbcd1378b4429665937ec681624a75dd8600ed
Detections:
win_stealc_auto
SH256 hash:
5b6f453442e99ca0239c4a0c9cd991ee3caed2451f0270ab61b1ebf107c40b71
MD5 hash:
9125b61d4d695ee282ec4a3884f95387
SHA1 hash:
ea80c13af0f1687e9851bf3236e4cca3d57cacc9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

Executable exe 018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c

(this sample)

Comments