MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16efe20ecbe454a3390e05e1641c91bbbf436a2ab1c830b76dc6c8a8b4843f14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 14


Intelligence 14 IOCs YARA 15 File information Comments

SHA256 hash: 16efe20ecbe454a3390e05e1641c91bbbf436a2ab1c830b76dc6c8a8b4843f14
SHA3-384 hash: 789ec0a917792ec7e3d9a1c6fd32d502f43ebff0a3dc0a931a64c3c9e2f79af0ec6a9049843aa72ed3e61f4f105511e2
SHA1 hash: 2517ee6b0331e10067fc6f4e79b0e237a9db3504
MD5 hash: 52f00e919a910e2445bcd4d35e896693
humanhash: sodium-maine-fanta-spaghetti
File name:16efe20ecbe454a3390e05e1641c91bbbf436a2ab1c830b76dc6c8a8b4843f14
Download: download sample
Signature Stealc
File size:788'992 bytes
First seen:2026-07-29 10:29:56 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c55db45c7490f797b5558c00406832fa (6 x Stealc)
ssdeep 12288:p6HSXamiqz8TbhvbTOMfJr6EmV8Mw0FVeyxBlDetAqxSv6c:JakzIbhvbCCJ+pVw0FVeyby
TLSH T117F48D1AA7A502E8E07BC175CA43C943EB7278565330979F03D54AB63F336A45B3EB11
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter JAMESWT_WT
Tags:43-228-157-66 exe Stealc StealC-v3

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Connection attempt
Sending an HTTP POST request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug base64 crypto fingerprint loader microsoft_visual_cc overlay packed stealc stealer
Verdict:
Malicious
Labled as:
Shellcode.Loader.Marte.X.Generic
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-19T11:04:00Z UTC
Last seen:
2026-07-30T19:52:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.StealC
Status:
Malicious
First seen:
2026-07-19 15:55:50 UTC
File Type:
PE+ (Exe)
Extracted files:
1
AV detection:
23 of 24 (95.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:stealc botnet:test stealer
Malware Config
C2 Extraction:
http://43.228.157.66
Unpacked files
SH256 hash:
16efe20ecbe454a3390e05e1641c91bbbf436a2ab1c830b76dc6c8a8b4843f14
MD5 hash:
52f00e919a910e2445bcd4d35e896693
SHA1 hash:
2517ee6b0331e10067fc6f4e79b0e237a9db3504
Detections:
win_stealc_auto
SH256 hash:
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
MD5 hash:
a8480ece517b8367ca8418d7888f410d
SHA1 hash:
49802c5598b2e9d94229ae987d0ac47bbf8977ea
Detections:
win_stealc_auto
Parent samples :
84bd20bcb88426402c4a3c96d8012396f83387a84b7abc1a6e90c2babebb42bd
b91cebec72ba934cde8ee67e8c4135c8c558d8ff46a70d3fdca83d9c37dd377b
290e9e54d6ff86cb4afc7acbbf10a06ed10f3fe476768dc96129a2a715208330
abb513eaa060b22c139fef518ba9b45785acd317ea6e01a945df346c9564eff7
764936d39ec0d9e3e00e04db2d6d3acc61b6bf77412ddc67ce180d6fbf665f58
fb924e8cef93d0a4244790ba1e1a4ecaf1a93b19f8e816329cdd763b017df459
bf24277400cc453d530e4277d3bd24e96c5e409adef6970518bdc59205aa0241
9a7c87d58a7ab1f2d99c5390d04c3875e41587b46f0632518e6108286ca45e2c
711199755fc55ac8185e64fe03bcc07aade1d449bd30e4bf7b898436d6eb3685
0215f734867bd71c57ff5c524d8cc670be5b4f1861b2c390cf46d18784a53624
efe7eb517cc449cc7721c5c0acfb8cf454f28fdf2f37c08854aad4deefd7edc9
1217681270b058cb08ff0eef8aad93219db13db2162a528d99267a354a85e62a
0f97b6a0c25560d63a863ff043a9556cb730ed6c8b20916eac98e2b969ab5f48
b7060387c40d51ac08a6e7ce33226b02f975ccfdc8ffa95c7412110e4adbe855
d5cad85a993f432900438b0b241f62226f2709cc7d2a0ab6897f58009eb4d670
1188d1f47cfc3797e1eb004e531b11b7a191a21475d97226dfa607db380b650b
dd0bebc17d103b682c00e5cc6f92ae28432a357cc9f9fc49f1747d28931c6402
9fe5f01662010999236f92b351ef36a759a58421fa4bca630c17e35e8cf8e0d9
354d3dc2b8997764925d5c42ee1c87acb4ba0bdca257edb7a2e63f53a4678c5c
526abca3f813871d7e2930c99bbe9c1d6a660cb7e6624e65e54154e4e3cf897d
252653fff0e5c8ce66326b2f105dcb74a728c76d78991773e385fa580c0833cf
e85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52
80b64331aab73ae1cb476c6a1dbe804abf304fded3d52303a700524e8370c92b
018cff3b8d3d9ecd0cdff35222c83d0859933652f5b368246a8641d96fa7154c
243aa79d0616ce126bd21133e2a06326eeb81104613e298a22d2cffaa292e2e7
4ed3931ab5bddd24ce23fd0d5546ae45b52a0cd0124afe7cb3692a56510ac1ed
61ab1d22949eac0582e989ae065ec4caee9ac99998276317edda96735cd311fb
0c16963f43604246e81f006d1f7df0a7258b36b929252c1502d92fea573d86aa
39e07fb60fbf206b06d1b5b2b74848d9d393c6bd66fd11e003436cd7ee6b5788
cea15fe7edd6b1b26f4326901781c16034ebe195cdb89ede2338e91c1d7ce6ac
16efe20ecbe454a3390e05e1641c91bbbf436a2ab1c830b76dc6c8a8b4843f14
798b6a521d6763f1b684f6d2a6c91e3eab92425dbd9265372a132aba1e213c5f
f901e1a138129e819f4759f30102e94a9987409f0978c9505c2d679d1a0880e2
ee2169a39bff9da6e3152e80a13b0bd9dc1e55c3ab191ca387bf8ede1ebdcd8d
8802527c317068b4b824d7bc1843dee0e52e047c7fae4997d577c11349c1ef01
de5b161afabe16c6de6a329454fb6bc2503a016431881e1a152b1ab755afc447
Malware family:
Stealc.v2
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Heuristics_ChromeABE
Author:Still
Description:attempts to match instructions related to Chrome App-bound Encryption elevation service; possibly spotted amongst infostealers
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:StealcV2
Author:Still
Description:attempts to match the instructions found in StealcV2
Rule name:StealcV2DateCheck
Author:kevoreilly
Description:StealcV2 date check bypass
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Trojan_Stealc_41db1d4d
Author:Elastic Security
Rule name:Windows_Trojan_Stealc_df3cdc7e
Author:Elastic Security
Rule name:win_mal_StealC_v2
Author:AlexMM
Description:Detects StealC v2
Rule name:win_stealc_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.stealc.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments