🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d84b7f1da20155f7eb5cec3eef61eec2eb92170034496611ae3ed6f08980b35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Stealc


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: 2d84b7f1da20155f7eb5cec3eef61eec2eb92170034496611ae3ed6f08980b35
SHA3-384 hash: 059b461d967837f2bb155c6eda0b17207903dcd5f6e18c20f3dc65221b6f4b2671f8571f5e73a3ba88cc3526e8a81adf
SHA1 hash: 00f873797cc53b49a6d5470a7130bcf0896bbc0f
MD5 hash: 942d4445a468496a7bb5eb15f9d9137b
humanhash: hotel-connecticut-lamp-stream
File name:2d84b7f1da20155f7eb5cec3eef61eec2eb92170034496611ae3ed6f08980b35
Download: download sample
Signature Stealc
File size:344'133 bytes
First seen:2025-09-12 15:48:33 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:rE6ZgWlv2qBO5cUoDSXkrfGAtYJLoZWx/naKPKYjHR2TZXBkSdgtaT+E+uBA1+IC:VqW9hUGpYJLb4TZvgIWueMJRC5JzoL
TLSH T18C746C1F67A503F8C4AF82B4CA56A453F77D740A2370E14F03E118B56F6B661ADAE720
TrID 25.4% (.ICL) Windows Icons Library (generic) (2059/9)
25.0% (.EXE) OS/2 Executable (generic) (2029/13)
24.7% (.EXE) Generic Win/DOS Executable (2002/3)
24.7% (.EXE) DOS Executable Generic (2000/1)
Magika pebin
Reporter mazznrz
Tags:exe Stealc

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
ID ID
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
microsoft_visual_cc obfuscated overlay packed
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
2d84b7f1da20155f7eb5cec3eef61eec2eb92170034496611ae3ed6f08980b35
MD5 hash:
942d4445a468496a7bb5eb15f9d9137b
SHA1 hash:
00f873797cc53b49a6d5470a7130bcf0896bbc0f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_detect_tls_callbacks
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:StealcV2
Author:Still
Description:attempts to match the instructions found in StealcV2
Rule name:StealcV2
Author:kevoreilly
Description:Stealc V2 Payload
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments