🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 127cd0e4e2d1178264eeb84d6a91e1aa6183f172a5998b1ecb6589386499256b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 16


Intelligence 16 IOCs YARA 25 File information Comments

SHA256 hash: 127cd0e4e2d1178264eeb84d6a91e1aa6183f172a5998b1ecb6589386499256b
SHA3-384 hash: f8e9f77d4f462888654802b2a2a6e93fa97b279a8396eb104180126f582489065fe81903574d8c88602bdb15ce35a2e8
SHA1 hash: a27b71b55e62d125e70ff9a3374b92aad8d1a557
MD5 hash: 644242d88cf382c4b58ce79c0f39469b
humanhash: yankee-south-six-paris
File name:127cd0e4e2d1178264eeb84d6a91e1aa6183f172a5998b1ecb6589386499256b
Download: download sample
Signature Stealc
File size:5'722'112 bytes
First seen:2025-09-19 08:22:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 646167cce332c1c252cdcb1839e0cf48 (8'474 x RedLineStealer, 4'855 x Amadey, 290 x Smoke Loader)
ssdeep 98304:HCwGbc57AsdyIYrOVWKIDsWqaYlrQwc7bv6FjtAiubtgxtme:HCYWsppWHDk7Rj0bCNz
Threatray 9 similar samples on MalwareBazaar
TLSH T1AE46334BFFEDC137C160A3355AD842A22A337B806536775FB343996748B3262B168367
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10522/11/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon f8f0f4c8c8c8d8f0 (8'804 x RedLineStealer, 5'109 x Amadey, 288 x Smoke Loader)
Reporter JAMESWT_WT
Tags:exe myftpupload-com Stealc

Intelligence


File Origin
# of uploads :
1
# of downloads :
102
Origin country :
IT IT
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
127cd0e4e2d1178264eeb84d6a91e1aa6183f172a5998b1ecb6589386499256b
Verdict:
Malicious activity
Analysis date:
2025-09-19 08:31:14 UTC
Tags:
amadey lumma stealer stealc rdp themida

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
vmdetect autorun
Result
Verdict:
Malware
Maliciousness:
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-vm CAB crypt cryptbot explorer installer installer lolbin microsoft_visual_cc packed rundll32 runonce sfx stealc
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-03-23T08:07:00Z UTC
Last seen:
2025-03-23T08:07:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
CAB:COMPRESSION:LZX Executable PDB Path PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.LummaStealer
Status:
Malicious
First seen:
2025-03-23 13:00:51 UTC
File Type:
PE (Exe)
Extracted files:
78
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:amadey family:lumma botnet:092155 defense_evasion discovery persistence spyware stealer trojan
Behaviour
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Checks installed software on the system
Checks BIOS information in registry
Checks computer location settings
Executes dropped EXE
Identifies Wine through registry keys
Reads user/profile data of local email clients
Identifies VirtualBox via ACPI registry values (likely anti-VM)
Amadey
Amadey family
Lumma Stealer, LummaC
Lumma family
Malware Config
C2 Extraction:
http://176.113.115.6
https://wxayfarer.live/ALosnz
https://esccapewz.run/ANSbwqy
https://travewlio.shop/ZNxbHi
https://touvrlane.bet/ASKwjq
https://sighbtseeing.shop/ASJnzh
https://advennture.top/GKsiio
https://targett.top/dsANGt
https://holidamyup.today/AOzkns
https://triplooqp.world/APowko
Unpacked files
SH256 hash:
127cd0e4e2d1178264eeb84d6a91e1aa6183f172a5998b1ecb6589386499256b
MD5 hash:
644242d88cf382c4b58ce79c0f39469b
SHA1 hash:
a27b71b55e62d125e70ff9a3374b92aad8d1a557
SH256 hash:
fee59ec37123951780aabf2f5c86cbd517efc6a83351fd3230eda250cf8ad509
MD5 hash:
e573c17042ceb169a36fea36d22dc2b7
SHA1 hash:
b8e1925a9fc170c059d3cf649231554510c8d7a6
Detections:
Amadey
SH256 hash:
a036b77bcd04aa434567d27376884081c2c2856b70831b538c9f27d92f9cf002
MD5 hash:
157ca501b599ee8bd872f4840cdc1285
SHA1 hash:
75579d12ba4b3b1f2ce862dde2e0f90fba5f738b
SH256 hash:
d02ff9536e1c2be6d551318f9fcb21053970ab60d14dd71ca18b348dcb309604
MD5 hash:
0112e404e94e177f0fe5aa9dac60da60
SHA1 hash:
e9309b6c45f56635bf9a66ff4880cd791d78ea97
Detections:
stealc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Amadey
Author:kevoreilly, YungBinary
Description:Amadey Payload
Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:detect_Redline_Stealer
Author:Varp0s
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:infostealer_win_stealc_standalone
Description:Find standalone Stealc sample based on decryption routine or characteristic strings
Reference:https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/
Rule name:malware_Stealc_str
Author:JPCERT/CC Incident Response Group
Description:Stealc infostealer
Rule name:MAL_Win_Amadey_Jun25
Author:0x0d4y
Description:This rule detects intrinsic patterns of Amadey version 5.34
Reference:https://0x0d4y.blog/amadey-targeted-analysis/
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Stealc
Author:kevoreilly
Description:Stealc Payload
Rule name:Stealer_Stealc
Author:Still
Description:attempts to match instructions/strings found in Stealc
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:vmdetect
Author:nex
Description:Possibly employs anti-virtualization techniques
Rule name:Windows_Generic_Threat_2bba6bae
Author:Elastic Security
Rule name:win_amadey_062025
Author:0x0d4y
Description:This rule detects intrinsic patterns of Amadey version 5.34.
Reference:https://0x0d4y.blog/amadey-targeted-analysis/
Rule name:WIN_FileFix_Detection
Author:dogsafetyforeverone
Description:Detects FileFix social engineering technique that launches chained PowerShell and PHP commands from file explorer typed paths
Reference:FileFix social engineering with PowerShell and PHP commands
Rule name:win_stealc_generic
Author:dubfib
Rule name:win_stealc_w0
Author:crep1x
Description:Find standalone Stealc sample based on decryption routine or characteristic strings
Reference:https://blog.sekoia.io/stealc-a-copycat-of-vidar-and-raccoon-infostealers-gaining-in-popularity-part-1/
Rule name:WIN_WebSocket_Base64_C2_20250726
Author:dogsafetyforeverone
Description:Detects configuration strings used by malware to specify WebSocket command-and-control endpoints inside Base64-encoded data. It looks for prefixes such as '#ws://' or '#wss://' that were found in QuasarRAT configuration data.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Stealc

Executable exe 127cd0e4e2d1178264eeb84d6a91e1aa6183f172a5998b1ecb6589386499256b

(this sample)

Comments