MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 124cf79f222ef8b88f4d0e2e474378c5a7ab8a3c513d2434037ef0acfd79c984. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 13


Intelligence 13 IOCs YARA 48 File information Comments

SHA256 hash: 124cf79f222ef8b88f4d0e2e474378c5a7ab8a3c513d2434037ef0acfd79c984
SHA3-384 hash: 263f09d9f6341be2ba32fa0515394e04f20d650c17f583a6e7c95693dfb0e66b3130d9db8a9ce35336900fc0baedf7e1
SHA1 hash: c23d33b86e22f305fd600145f27f6a9522e29cc0
MD5 hash: ff1b216b6ef02dceda621ca45ed4f0c3
humanhash: lion-hawaii-single-uranus
File name:1.exe
Download: download sample
Signature Stealc
File size:3'242'496 bytes
First seen:2026-08-06 05:37:12 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ebc247a77b4d4a804b261f97a1fd075c (91 x Vidar, 26 x Smoke Loader, 20 x RemusStealer)
ssdeep 49152:VbXJAziaUp62zIVATR/jSu7UR4Sh9YQd1u2oiVK/:VbZaFwTUu7UOPQdUd
TLSH T132E57C877CA108F6C4AA95318932E6667B61BC480F2153D72ED0BE3A3FB6BE05D75704
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 2008e460b9b00028 (1 x RedLineStealer, 1 x AsyncRAT, 1 x Stealc)
Reporter abuse_ch
Tags:exe Stealc

Intelligence


File Origin
# of uploads :
1
# of downloads :
186
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-08-06 05:50:41 UTC
Tags:
stealer payload stealc loader solaris auto-reg cryptbot purehvnc delphi inno installer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Launching a process
Creating a window
Using the Windows Management Instrumentation requests
Reading critical registry keys
Changing a file
Connecting to a non-recommended domain
Connection attempt
Sending an HTTP POST request
Running batch commands
Creating a process with a hidden window
Launching the process to change network settings
Sending an HTTP GET request
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file in the %AppData% subdirectories
Enabling the 'hidden' option for recently created files
Searching for synchronization primitives
Creating a file in the %AppData% directory
Creating a file
Enabling the 'hidden' option for files in the %temp% directory
Stealing user critical data
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Connection attempt to an infection source
Unauthorized injection to a system process
Enabling autorun by creating a file
Sending an HTTP POST request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm crypto golang
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-05T15:17:00Z UTC
Last seen:
2026-08-08T02:53:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Changes memory attributes in foreign processes to executable or writable
Changes the view of files in windows explorer (hidden files and folders)
Connects to many ports of the same IP (likely port scanning)
Contains functionality to check for running processes (XOR)
Contains functionality to inject code into remote processes
Contains functionality to inject threads in other processes
Contains functionality to log keystrokes
Creates a thread in another existing process (thread injection)
Creates multiple autostart registry keys
Found direct / indirect Syscall (likely to bypass EDR)
Found evasive API chain (may stop execution after checking mutex)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Monitors registry run keys for changes
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potentially malicious time measurement code found
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sample uses process hollowing technique
Sets debug register (to hijack the execution of another thread)
Sigma detected: Capture Wi-Fi password
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: New RUN Key Pointing to Suspicious Folder
Suricata IDS alerts for network traffic
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Unusual module load detection (module proxying)
Uses netsh to dump wireless credentials
Uses netsh to modify the Windows network and firewall settings
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1953094 Sample: 1.exe Startdate: 06/08/2026 Architecture: WINDOWS Score: 100 114 Suricata IDS alerts for network traffic 2->114 116 Malicious sample detected (through community Yara rule) 2->116 118 Antivirus detection for URL or domain 2->118 120 8 other signatures 2->120 10 1.exe 2->10         started        13 wlrmdr.exe 2->13         started        process3 signatures4 158 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 10->158 160 Writes to foreign memory regions 10->160 162 Allocates memory in foreign processes 10->162 170 4 other signatures 10->170 15 HelpPane.exe 47 10->15         started        164 Antivirus detection for dropped file 13->164 166 Multi AV Scanner detection for dropped file 13->166 168 Found evasive API chain (may stop execution after checking mutex) 13->168 172 3 other signatures 13->172 process5 dnsIp6 102 192.162.199.186, 49719, 49721, 80 FEMOITGB United Kingdom 15->102 104 62.60.226.232, 49718, 49720, 80 FEMOITGB Germany 15->104 66 C:\Users\user\...59FAB5FDF6D4DA2A827.exe, PE32 15->66 dropped 68 C:\Users\user\...\C99CA1A18F9E4A1F92A2.exe, PE32 15->68 dropped 70 C:\Users\user\...\B4A25E61783F48FE8A14.exe, PE32+ 15->70 dropped 72 3 other malicious files 15->72 dropped 108 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 15->108 110 Queries DNS domain through GetComputerNameExW (potential sandbox evasion) 15->110 112 Tries to detect sandboxes / dynamic malware analysis system (Installed program check) 15->112 20 B4A25E61783F48FE8A14.exe 1 14 15->20         started        25 C99CA1A18F9E4A1F92A2.exe 15->25         started        27 E59FAB5FDF6D4DA2A827.exe 15->27         started        29 2 other processes 15->29 file7 signatures8 process9 dnsIp10 100 196.251.107.186 FEMOITGB Germany 20->100 74 C:\Users\user\AppData\Roaming\...\wlrmdr.exe, PE32+ 20->74 dropped 76 C:\Users\user\AppData\Local\...\v9i6y12s.exe, PE32 20->76 dropped 78 C:\Users\user\AppData\Local\...\u5drvzjt.exe, PE32 20->78 dropped 86 3 other malicious files 20->86 dropped 144 Antivirus detection for dropped file 20->144 146 Multi AV Scanner detection for dropped file 20->146 148 Changes the view of files in windows explorer (hidden files and folders) 20->148 156 11 other signatures 20->156 31 7hrsvm3d.exe 20->31         started        34 explorer.exe 30 2 20->34 injected 36 68neug1r.exe 20->36         started        47 11 other processes 20->47 80 C:\Users\user\...\C99CA1A18F9E4A1F92A2.tmp, PE32 25->80 dropped 38 C99CA1A18F9E4A1F92A2.tmp 25->38         started        82 C:\Users\user\...59FAB5FDF6D4DA2A827.tmp, PE32 27->82 dropped 41 E59FAB5FDF6D4DA2A827.tmp 27->41         started        84 C:\Users\user\AppData\...\audiodgmzz.exe, PE32+ 29->84 dropped 150 Creates multiple autostart registry keys 29->150 152 Uses netsh to modify the Windows network and firewall settings 29->152 154 Uses netsh to dump wireless credentials 29->154 43 netsh.exe 2 29->43         started        45 conhost.exe 29->45         started        file11 signatures12 process13 dnsIp14 174 Multi AV Scanner detection for dropped file 31->174 176 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 31->176 178 Writes to foreign memory regions 31->178 192 4 other signatures 31->192 50 HelpPane.exe 31->50         started        53 68neug1r.exe 34->53         started        55 68neug1r.exe 34->55         started        57 audiodgmzz.exe 34->57         started        59 audiodgmzz.exe 34->59         started        180 Antivirus detection for dropped file 36->180 182 Contains functionality to check for running processes (XOR) 36->182 184 Changes memory attributes in foreign processes to executable or writable 36->184 194 2 other signatures 36->194 88 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 38->88 dropped 90 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 38->90 dropped 186 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 38->186 92 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 41->92 dropped 106 196.251.107.131 FEMOITGB Germany 47->106 94 C:\Users\user\AppData\Local\...\u5drvzjt.tmp, PE32 47->94 dropped 188 Monitors registry run keys for changes 47->188 190 Unusual module load detection (module proxying) 47->190 61 u5drvzjt.tmp 47->61         started        file15 signatures16 process17 file18 122 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 50->122 124 Tries to harvest and steal browser information (history, passwords, etc) 50->124 126 Writes to foreign memory regions 50->126 142 3 other signatures 50->142 64 chrome.exe 50->64         started        128 Changes memory attributes in foreign processes to executable or writable 53->128 130 Allocates memory in foreign processes 53->130 132 Modifies the context of a thread in another process (thread injection) 53->132 134 Found direct / indirect Syscall (likely to bypass EDR) 53->134 136 Antivirus detection for dropped file 57->136 138 Multi AV Scanner detection for dropped file 57->138 140 Unusual module load detection (module proxying) 57->140 96 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 61->96 dropped 98 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 61->98 dropped signatures19 process20
Gathering data
Threat name:
Win64.Downloader.Banload
Status:
Suspicious
First seen:
2026-08-05 22:20:09 UTC
File Type:
PE+ (Exe)
Extracted files:
2
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
svcstealer
Score:
  10/10
Tags:
family:svcstealer discovery downloader execution persistence privilege_escalation stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Browser Information Discovery
Event Triggered Execution: Netsh Helper DLL
Executes a command shell one-liner
Suspicious use of SetThreadContext
Detects SvcStealer Payload
Family: SvcStealer, Diamotrix
Unpacked files
SH256 hash:
124cf79f222ef8b88f4d0e2e474378c5a7ab8a3c513d2434037ef0acfd79c984
MD5 hash:
ff1b216b6ef02dceda621ca45ed4f0c3
SHA1 hash:
c23d33b86e22f305fd600145f27f6a9522e29cc0
Malware family:
SolarisLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:CMD_Ping_Localhost
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__ConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:Glasses
Author:Seth Hardy
Description:Glasses family
Rule name:GlassesCode
Author:Seth Hardy
Description:Glasses code features
Rule name:GoBinTest
Rule name:golang
Rule name:Golangmalware
Author:Dhanunjaya
Description:Malware in Golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:grakate_stealer_nov_2021
Rule name:HiveRansomware
Author:Dhanunjaya
Description:Yara Rule To Detect Hive V4 Ransomware
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:INDICATOR_SUSPICIOUS_Binary_Embedded_Crypto_Wallet_Browser_Extension_IDs
Author:ditekSHen
Description:Detect binaries embedding considerable number of cryptocurrency wallet browser extension IDs.
Rule name:INDICATOR_SUSPICIOUS_Binary_Embedded_MFA_Browser_Extension_IDs
Author:ditekSHen
Description:Detect binaries embedding considerable number of MFA browser extension IDs.
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore
Author:ditekSHen
Description:Detects executables containing SQL queries to confidential data stores. Observed in infostealers
Rule name:INDICATOR_SUSPICIOUS_GENInfoStealer
Author:ditekSHen
Description:Detects executables containing common artifacts observed in infostealers
Rule name:INDICATOR_SUSPICIOUS_References_SecTools
Author:ditekSHen
Description:Detects executables referencing many IR and analysis tools
Rule name:INDICATOR_SUSPICIOUS_ReflectiveLoader
Author:ditekSHen
Description:Detects Reflective DLL injection artifacts
Rule name:Macos_Infostealer_Wallets_8e469ea0
Author:Elastic Security
Rule name:pe_detect_tls_callbacks
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:recordbreaker_win_generic
Author:_kphi
Rule name:ReflectiveLoader
Author:Florian Roth (Nextron Systems)
Description:Detects a unspecified hack tool, crack or malware using a reflective loader - no hard match - further investigation recommended
Reference:Internal Research
Rule name:RemusStealer_GoPayload
Author:burger
Description:Detects RemusStealer Go-compiled payload
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:telebot_framework
Author:vietdx.mb
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

Executable exe 124cf79f222ef8b88f4d0e2e474378c5a7ab8a3c513d2434037ef0acfd79c984

(this sample)

  
Delivery method
Distributed via web download

Comments