MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3834d0dec7d98a02845b4dee85fde459612448951a5ea312f77e17db0f29b479. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PidoStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 6 File information Comments

SHA256 hash: 3834d0dec7d98a02845b4dee85fde459612448951a5ea312f77e17db0f29b479
SHA3-384 hash: 5abe8d5d0aefe43aabbfcc7b505a673f64dbf64c7e419aa3fdb51c4e2a09221252d51de728527bef4463f12ad61d5dc9
SHA1 hash: dd3e1774fec862cf37a6036a1d87b03022eb287b
MD5 hash: 94ac6ca3eed1d8c81e0a8006b0175ddc
humanhash: mountain-river-july-pennsylvania
File name:94ac6ca3eed1d8c81e0a8006b0175ddc.exe
Download: download sample
Signature PidoStealer
File size:56'772'891 bytes
First seen:2026-08-29 06:25:30 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 88016fcdef7f227c62171d0afad9aae4 (20 x ValleyRAT, 17 x OffLoader, 11 x Tofsee)
ssdeep 1572864:nO7mvZsAiLQad3HeTF3zIc1hxP7akIAyYbPmdYCPkJC:O7mvZ7iky3HeTF33fTakIAy+9CPkY
TLSH T1B0C7333BB18B353EE46E553AB972D9001C3F6A55A9528C0646E8DC4CDF384701E3DBAB
TrID 61.4% (.EXE) Inno Setup installer (107240/4/30)
23.8% (.EXE) Win32 EXE PECompact compressed (generic) (41569/9/9)
3.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
3.7% (.EXE) Win64 Executable (generic) (6522/11/2)
2.5% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 70d8e6e0e0a6c870 (2 x CobaltStrike, 1 x PidoStealer)
Reporter abuse_ch
Tags:exe PidoStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
170
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-29 06:38:11 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Creating a window
Creating a process from a recently created file
Сreating synchronization primitives
Searching for synchronization primitives
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug crypto embarcadero_delphi evasive fingerprint inno installer installer installer-heuristic packed reconnaissance
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-26T05:32:00Z UTC
Last seen:
2026-08-30T00:39:00Z UTC
Hits:
~100
Result
Threat name:
Pido Stealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
88 / 100
Signature
Antivirus detection for dropped file
Drops large PE files
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Icon mismatch, binary includes an icon from a different legit application in order to fool users
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Capture Wi-Fi password
Suricata IDS alerts for network traffic
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal WLAN passwords
Tries to steal Mail credentials (via file / registry access)
Uses netsh to dump wireless credentials
Uses netsh to modify the Windows network and firewall settings
Uses the Telegram API (likely for C&C communication)
Yara detected Generic Stealer
Yara detected Pido Stealer
Yara detected Telegram RAT
Yara detected Telegram Recon
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1965664 Sample: 3UAnHYS5Ce.exe Startdate: 29/08/2026 Architecture: WINDOWS Score: 88 81 api.telegram.org 2->81 83 td.telegram.org 2->83 85 2 other IPs or domains 2->85 99 Suricata IDS alerts for network traffic 2->99 101 Found malware configuration 2->101 103 Antivirus detection for dropped file 2->103 107 11 other signatures 2->107 10 3UAnHYS5Ce.exe 2 2->10         started        13 chinese.exe 2->13         started        16 chinese.exe 2->16         started        signatures3 105 Uses the Telegram API (likely for C&C communication) 81->105 process4 file5 69 C:\Users\user\AppData\...\3UAnHYS5Ce.tmp, PE32 10->69 dropped 18 3UAnHYS5Ce.tmp 23 16 10->18         started        111 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 13->111 113 Tries to steal Mail credentials (via file / registry access) 13->113 115 Tries to harvest and steal browser information (history, passwords, etc) 13->115 117 3 other signatures 13->117 22 netsh.exe 13->22         started        24 netsh.exe 13->24         started        signatures6 process7 file8 53 C:\Users\user\...\tsetup-x64.7.1.1.exe (copy), PE32 18->53 dropped 55 C:\Users\user\AppData\...\is-9TWX6S5HXX.tmp, PE32 18->55 dropped 57 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 18->57 dropped 59 4 other malicious files 18->59 dropped 109 Found many strings related to Crypto-Wallets (likely being stolen) 18->109 26 tsetup-x64.7.1.1.exe 2 18->26         started        29 chinese.exe 14 10 18->29         started        33 conhost.exe 22->33         started        35 conhost.exe 24->35         started        signatures9 process10 dnsIp11 71 C:\Users\user\...\tsetup-x64.7.1.1.tmp, PE32 26->71 dropped 37 tsetup-x64.7.1.1.tmp 30 18 26->37         started        93 ip-api.com 208.95.112.1, 49711, 49715, 80 TUT-AS-TotalUptimeTechnologiesLLCUS United States 29->93 95 api.telegram.org 149.154.166.110, 443, 49713, 49716 TELEGRAMVG United Kingdom 29->95 97 icanhazip.com 104.16.184.241, 49712, 49714, 80 CLOUDFLARENET-CloudflareIncUS Canada 29->97 73 C:\Users\user\AppData\...\chinese.exe.log, CSV 29->73 dropped 119 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 29->119 121 Tries to steal Mail credentials (via file / registry access) 29->121 123 Found many strings related to Crypto-Wallets (likely being stolen) 29->123 125 5 other signatures 29->125 40 netsh.exe 2 29->40         started        42 netsh.exe 2 29->42         started        file12 signatures13 process14 file15 61 C:\Users\user\AppData\...\unins000.exe (copy), PE32 37->61 dropped 63 C:\Users\user\AppData\...\is-JVJUB.tmp, PE32+ 37->63 dropped 65 C:\Users\user\...\d3dcompiler_47.dll (copy), PE32+ 37->65 dropped 67 6 other malicious files 37->67 dropped 44 Telegram.exe 37->44         started        49 conhost.exe 40->49         started        51 conhost.exe 42->51         started        process16 dnsIp17 87 149.154.175.53, 443, 49727, 49732 TELEGRAM_MESSENGERVG United States 44->87 89 149.154.175.56, 443, 49726, 49730 TELEGRAM_MESSENGERVG United States 44->89 91 5 other IPs or domains 44->91 75 C:\Users\user\AppData\...\d3dcompiler_47.dll, PE32+ 44->75 dropped 77 C:\Users\user\AppData\Roaming\...\Updater.exe, PE32+ 44->77 dropped 79 C:\Users\user\AppData\...\Telegram.exe, PE32+ 44->79 dropped 127 Found many strings related to Crypto-Wallets (likely being stolen) 44->127 file18 signatures19
Gathering data
Threat name:
ByteCode-MSIL.Trojan.MassLogger
Status:
Malicious
First seen:
2026-08-25 12:36:08 UTC
File Type:
PE (Exe)
Extracted files:
26
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
collection discovery installer persistence privilege_escalation spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Inno Setup is an open-source installation builder for Windows applications.
Browser Information Discovery
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Wi-Fi Discovery
Accesses Microsoft Outlook profiles
Checks installed software on the system
Drops desktop.ini file(s)
Looks up external IP address via web service
Creates a file in the Startup directory
Executes dropped EXE
Loads dropped DLL
Reads WinSCP keys stored on the system
Reads user/profile data of web browsers
Malware family:
IntelIXStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Borland
Author:malware-lu
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:pe_detect_tls_callbacks
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments